Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US criticises Australia’s proposed algorithm opt-out laws as ‘censorship’

    September 23, 2026

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    September 23, 2026

    XRP volume explodes to $7.4B, and a massive CME short squeeze is blamed

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US criticises Australia’s proposed algorithm opt-out laws as ‘censorship’
    • Sweden fines Miljödata $183,000 over breach affecting 2.2 million
    • XRP volume explodes to $7.4B, and a massive CME short squeeze is blamed
    • ‘Peeing a jellyfish’: Children’s ketamine injuries revealed
    • World Rhino Day: What does it take to save a species?
    • Trump, Guterres Address UNGA With Contrasting Messages
    • Did Obama ban Fox News from White House briefings? Claim distorts the facts
    • Morocco election: How Ceuta, football and Israel have shaped the campaign
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 06, 2026IoT Security / Malware

    Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.

    According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

    They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The “phone home” implants have been codenamed ENDLESSDOORS.

    “ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux),” Jacob Baines, VulnCheck Chief Technology Officer, said. “Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server.”

    “The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”

    Cybersecurity

    The “kworker” worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that’s configured to contact the following –

    • 47.107.224[.]89
    • rbdg4nzqadui[.]wikaba[.]com

    What’s more, there is no handshake, negotiation, or authentication involved. Once the implant sends a “hello” message to the server alongside the LAN MAC address, it’s engineered to run whatever the server sends back in response.

    “One reserved string, rctlbash, tells the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn /bin/sh, and bridge it,” Baines explained. “That is a live interactive root shell.”

    “The vocabulary of this protocol is two phrases: run this as root, and give me a root shell. Anyone along the network path can hijack the client/server communication. Anyone who controls the resolution of rbdg4nzqadui.wikaba[.]com, or the address it resolves to, can control any ENDLESSDOORS implant that tries to phone home.”

    An attacker can take advantage of this loophole to hijack the outbound rctl communications and obtain a live root shell, and take over control of the router without having to be reachable from the internet.

    VulnCheck noted that every firmware listed on zbtlink.com’s download page embeds the rctl implant and starts it at boot with an init.d script named “skworker.” The list of affected models is below –

    • CPE2801
    • WE1026-5G-WD
    • WE1326
    • WE2007
    • WE2008-DSIM
    • WE2416
    • WE3326
    • WE5927
    • WE5931
    • WE5931AC
    • WE826-T3-DSIM
    • WG108
    • WG1602
    • WG1608-DSIM
    • WG209
    • WG2105
    • WG2107
    • WG259
    • WG3526
    • Z8102AX-2DSIM
    Cybersecurity

    Each of these models have been found to have been found to dial the same set of four primary and secondary endpoints –

    • zbtctl.epplink[.]net (47.100.190[.]96)
    • 47.107.224[.]89
    • online-string[.]com (45.32.81[.]152)
    • rbdg4nzqadui.wikaba[.]com (43.248.136[.]125)

    As of writing, users visiting the firmware downloads page on Zbtlink’s website are displayed the below message –

    We have detected firmware security vulnerabilities affecting selected router firmware releases.

    As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.

    We will notify you immediately once the fixed, security-validated firmware is available for release.

    We apologize for the inconvenience caused. Thank you for your understanding.

    The Hacker News has contacted the Chinese router manufacturer for further comment, and we will update the story if we hear back.

    In the meantime, customers are advised to check the process list, scan the file system for files like /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker, and block the egress points.

    Backdoor ChineseMade opens Root routers Shells Ship unauthenticated Zbtlink
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US criticises Australia’s proposed algorithm opt-out laws as ‘censorship’

    September 23, 2026

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    September 23, 2026

    XRP volume explodes to $7.4B, and a massive CME short squeeze is blamed

    September 23, 2026

    ‘Peeing a jellyfish’: Children’s ketamine injuries revealed

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US criticises Australia’s proposed algorithm opt-out laws as ‘censorship’

    September 23, 2026

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    September 23, 2026

    XRP volume explodes to $7.4B, and a massive CME short squeeze is blamed

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.