On Thursday, August 27, US cybersecurity company VulnCheck revealed that routers manufactured by Shenzhen Zbtlink Electronics come with built-in monitoring capabilities that can be controlled remotely.
Earlier this month, researchers disclosed that over 20 models of routers produced by Zbtlink came pre-installed with backdoors at the time of manufacture, automatically communicating with specific IP addresses and domains registered in China every 35 seconds.
Located in Massachusetts, VulnCheck’s Chief Technology Officer Jacob Baines disclosed in a recent blog post the discovery of two new implanted programs named “Darklantern” and “Speakingstone.” These backdoors have been around longer than the previously discovered “Endlessdoors” backdoor reported at the beginning of the month.
Baines mentioned that these two backdoors allow for easy access to information within the network where the affected routers are located. The “Speakingstone” backdoor specifically has functionalities such as modifying DNS settings, establishing reverse SSH connections, sending back device information, and executing remote commands, posing significant security risks.
Following VulnCheck’s public announcement about the presence of the “Endlessdoors” backdoor in over 20 Zbtlink routers, Zbtlink halted the sale of related routers and took affected software offline from their website. The company claimed that the mentioned programs were actually remote access support features meant for after-sales maintenance, never used for malicious purposes.
Zbtlink Electronics routers are sold globally. The company is not a well-known consumer electronics brand; they primarily manufacture router equipment which are then rebranded and sold by other companies.
VulnCheck pointed out that users may not be aware that their devices utilize Zbtlink hardware or firmware.
Baines warned, “Just because you haven’t heard of Zbtlink doesn’t mean it’s not being sold elsewhere. Where Zbtlink’s hardware goes, its firmware and implanted programs follow.”
He mentioned that routers with Speakingstone installed attempt to connect to an unregistered backup domain. VulnCheck researchers subsequently registered the domain and set up a sinkhole server for observing related communications. Since then, researchers have started receiving connections and device information from affected routers.
VulnCheck observed that 392 Zbtlink devices were reconnecting to the backup domain, with 390 showing network locations inside China, approximately 83% using China Mobile networks. Among these devices, the one with the longest running time had been continuously sending signals for two years.
Researchers also discovered that the Speakingstone implanted program within Zbtlink-related firmware appeared on a batch of models with highly consistent firmware versions, predominantly on devices using China Mobile networks. Out of the 392 reconnecting devices, 363 belonged to the same model, running the same firmware version.
The Chinese authorities have a long history of monitoring citizens on the internet.
VulnCheck believes that this indicates “local monitoring technology in China has been extensively deployed on Chinese networks,” but these routers are also sold globally, including in the United States.
Zbtlink spokesperson Michael Xia responded to Reuters via email, stating that the remote support tools and cloud access features in their products are legitimate and for authorized post-sales maintenance only.
He mentioned that the remote access methods in question “do not pose any security risks, and we place high importance on product security.”
Xia did not address the issue of alleged monitoring capabilities and did not respond to VulnCheck’s doubts regarding the legitimacy of their implanted programs as remote support tools.
Baines concluded in his blog post by emphasizing that these Zbtlink routers should not be allowed on American networks.
“These are routers with built-in monitoring capabilities, manufactured in China, sold to unsuspecting consumers, and their backdoors can easily be exploited by any attacker who finds them,” wrote Baines. “These are not theoretical risks or minor vulnerabilities but actual, verifiable implanted programs. We have the beacons, scan results, and root privileges.”
