ELSEIF
Your brief EB
502 stories from 211 feeds 1261 clusters Refreshed 8 minutes ago next pull 18:51

SECURITY Signal 71

Three distinct firmware implants discovered in ZBT routers sold globally

VulnCheck identified three separate backdoor-like implants, ENDLESSDOORS, DARKLANTERN, and SPEAKINGSTONE, embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics and sold under many brands worldwide.

WHY IT MATTERS

The implants give remote attackers root-level control, can exfiltrate credentials, rewrite DNS settings, and operate even behind NAT, posing a severe security risk for networks that use these devices. Engineers must treat affected ZBT models as compromised, update firmware where possible, and consider replacing them to prevent unauthorized access.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

ENDLESSDOORS runs as a disguised kernel process, contacts a hard-coded command-and-control server, and executes arbitrary root commands.

02

DARKLANTERN opens an unauthenticated UDP listener on port 9992, allowing any internet host to query device info and run commands as root.

03

SPEAKINGSTONE beacons outbound over UDP port 10000, can steal PPPoE credentials, modify DNS, and establish reverse SSH tunnels even when the router is behind a firewall.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Tomshardware Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware Open ↗