Published 12 hours ago • loading... • Updated 1 hour ago
Researchers discover additional backdoors in Chinese-made Zbtlink routers
VulnCheck said the implants can expose network data and redirect traffic, while Zbtlink suspended router sales and pulled affected software offline.
Cybersecurity firm VulnCheck identified two previously unreported backdoors, Darklantern and Speakingstone, in more than a dozen Chinese-made Zbtlink router models enabling invasive remote access researchers describe as "surveillance."
Weeks earlier, VulnCheck disclosed "Endlessdoors," a backdoor present in more than 20 Zbtlink routers; the two new backdoors had actually preceded that discovery on certain models.
VulnCheck CTO Jacob Baines discovered Speakingstone by registering an unregistered domain the compromised devices attempted to contact, calling it a "surveillance implant" and warning organizations may unknowingly own infected routers sold worldwide under various brand names.
One day after the disclosure, Zbtlink suspended sales and pulled affected software offline, though spokesperson Michael Xia claimed the remote-access functions are "legitimate remote support and cloud access functions intended solely for authorized after-sales maintenance" posing no security risks.
Data showing most affected routers active in China led researchers to characterize the implants as "domestic Chinese surveillance technology, deployed against Chinese citizens" while the same functionality remains sold globally, including in the U.S.