this post was submitted on 10 Aug 2026
65 points (100.0% liked)

Technology

86982 readers
5616 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://mander.xyz/post/56484546

Here is the technical report: ENDLESSDOORS Is Phoning Home. Pick Up.

...

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS.

"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. "Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server."

"The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell." Cybersecurity

The "kworker" worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that's configured to contact the following -

...

top 11 comments
sorted by: hot top controversial new old
[–] RedGreenBlue@lemmy.zip 1 points 23 minutes ago

But can i put pfsense or something on it?

[–] esc@piefed.social 3 points 1 hour ago

At least they should have good openwrt support!

[–] tinsuke@lemmy.world 19 points 4 hours ago (3 children)

That ough to be one of the laziest genAI slop images for a "Chinese router with a backdoor".

Damn, it's bad.

[–] pHr34kY@lemmy.world 1 points 16 minutes ago

That flag. Ugh.

There was a time when by facebook wall was plastered with AI slop articles, and all of them had flags chucked in like this.

[–] greyscale@lemmy.grey.ooo 8 points 2 hours ago

Yeah that one is fairly hideous. Why can't they just use a product shot?

[–] A_norny_mousse@piefed.zip 1 points 1 hour ago* (last edited 1 hour ago)

A report of China obviously and illegally spying on large amounts of people (not only in the USA I might add), and that's the top comment?

[–] truthfultemporarily@feddit.org 7 points 4 hours ago (1 children)

Another case of: use an American router against the Chinese backdoor behind a Chinese router against the American backdoor.

(Or just do open source)

[–] AllNewTypeFace@leminal.space 2 points 2 hours ago

throw an Indian router, an Israeli router and a Turkish router into the chain for extra security

[–] XLE@piefed.social 6 points 4 hours ago (2 children)

oh COME ON. The last thing I needed in this jingoistic American economy was any reason to legitimize their crap

[–] A_norny_mousse@piefed.zip 3 points 1 hour ago

Do you mean, legitimize the USA being anti-China?

I think it's important to remember that the USA aren't the only bad player on the globe.

[–] NaibofTabr@infosec.pub 6 points 3 hours ago* (last edited 3 hours ago)

I mean... did you miss all the reporting on Salt Typhoon and Volt Typhoon?