Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Meta launches Muse Code, an AI agent for large code bases

    August 6, 2026

    Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel

    August 6, 2026

    Hackers run khunt post-exploitation toolkit from Oracle database

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meta launches Muse Code, an AI agent for large code bases
    • Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel
    • Hackers run khunt post-exploitation toolkit from Oracle database
    • FBI Agent Accused Of $1 Million Crypto Theft
    • THC medication made PTSD nightmares disappear for more than a third of patients
    • On a Philippine beach, villagers are stepping up to save sea turtle nests
    • License alignment buys time to pick production solution for new UK North Sea oil hub
    • Iranian footballers who defied Tehran become Australian citizens
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 06, 2026IoT Security / Malware

    Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.

    According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

    They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The “phone home” implants have been codenamed ENDLESSDOORS.

    “ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux),” Jacob Baines, VulnCheck Chief Technology Officer, said. “Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server.”

    “The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”

    Cybersecurity

    The “kworker” worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that’s configured to contact the following –

    • 47.107.224[.]89
    • rbdg4nzqadui[.]wikaba[.]com

    What’s more, there is no handshake, negotiation, or authentication involved. Once the implant sends a “hello” message to the server alongside the LAN MAC address, it’s engineered to run whatever the server sends back in response.

    “One reserved string, rctlbash, tells the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn /bin/sh, and bridge it,” Baines explained. “That is a live interactive root shell.”

    “The vocabulary of this protocol is two phrases: run this as root, and give me a root shell. Anyone along the network path can hijack the client/server communication. Anyone who controls the resolution of rbdg4nzqadui.wikaba[.]com, or the address it resolves to, can control any ENDLESSDOORS implant that tries to phone home.”

    An attacker can take advantage of this loophole to hijack the outbound rctl communications and obtain a live root shell, and take over control of the router without having to be reachable from the internet.

    VulnCheck noted that every firmware listed on zbtlink.com’s download page embeds the rctl implant and starts it at boot with an init.d script named “skworker.” The list of affected models is below –

    • CPE2801
    • WE1026-5G-WD
    • WE1326
    • WE2007
    • WE2008-DSIM
    • WE2416
    • WE3326
    • WE5927
    • WE5931
    • WE5931AC
    • WE826-T3-DSIM
    • WG108
    • WG1602
    • WG1608-DSIM
    • WG209
    • WG2105
    • WG2107
    • WG259
    • WG3526
    • Z8102AX-2DSIM
    Cybersecurity

    Each of these models have been found to have been found to dial the same set of four primary and secondary endpoints –

    • zbtctl.epplink[.]net (47.100.190[.]96)
    • 47.107.224[.]89
    • online-string[.]com (45.32.81[.]152)
    • rbdg4nzqadui.wikaba[.]com (43.248.136[.]125)

    As of writing, users visiting the firmware downloads page on Zbtlink’s website are displayed the below message –

    We have detected firmware security vulnerabilities affecting selected router firmware releases.

    As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.

    We will notify you immediately once the fixed, security-validated firmware is available for release.

    We apologize for the inconvenience caused. Thank you for your understanding.

    The Hacker News has contacted the Chinese router manufacturer for further comment, and we will update the story if we hear back.

    In the meantime, customers are advised to check the process list, scan the file system for files like /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker, and block the egress points.

    Backdoor ChineseMade opens Root routers Shells Ship unauthenticated Zbtlink
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers run khunt post-exploitation toolkit from Oracle database

    Why security validation must follow the attack path

    Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

    Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Meta launches Muse Code, an AI agent for large code bases

    August 6, 2026

    Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel

    August 6, 2026

    Hackers run khunt post-exploitation toolkit from Oracle database

    August 6, 2026

    FBI Agent Accused Of $1 Million Crypto Theft

    August 6, 2026
    Latest Posts

    Can you identify Taylor Farms products by codes beginning with ‘TF’ printed on bags?

    July 23, 2026

    The Guardian view on Britain’s uninhabitable homes: as temperatures rise, a new approach is needed | Editorial

    July 23, 2026

    Can Wisconsin voters void a returned absentee ballot?

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Meta launches Muse Code, an AI agent for large code bases

    August 6, 2026

    Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel

    August 6, 2026

    Hackers run khunt post-exploitation toolkit from Oracle database

    August 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.