this post was submitted on 10 Aug 2026
291 points (97.7% liked)

Technology

88183 readers
3010 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://mander.xyz/post/56484546

Here is the technical report: ENDLESSDOORS Is Phoning Home. Pick Up.

...

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS.

"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. "Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server."

"The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell." Cybersecurity

The "kworker" worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that's configured to contact the following -

...

all 46 comments
sorted by: hot top controversial new old
[–] tinsuke@lemmy.world 67 points 1 month ago (3 children)

That ough to be one of the laziest genAI slop images for a "Chinese router with a backdoor".

Damn, it's bad.

[–] greyscale@lemmy.grey.ooo 31 points 1 month ago (1 children)

Yeah that one is fairly hideous. Why can't they just use a product shot?

[–] apftwb@lemmy.world 7 points 1 month ago (1 children)
[–] greyscale@lemmy.grey.ooo 1 points 1 month ago* (last edited 1 month ago)

therapist: the mimo spider can't get you

the mimo spider:

[–] A_norny_mousse@piefed.zip 7 points 1 month ago* (last edited 1 month ago) (1 children)

A report of China obviously and illegally spying on large amounts of people (not only in the USA I might add), and that's the top comment?

[–] LincolnsDogFido@lemmy.zip 1 points 1 month ago (1 children)

I mean, it was assumed and mostly known that it was taking place already. Thats why the government tried to prevent them from being sold in the US. Did anyone really think they were going to give up on spying on world citizens when they were forced to sell TikTok?

[–] A_norny_mousse@piefed.zip 3 points 1 month ago

No. But a hardware backdoor is a big step from whatever TikTok is doing. And I know it's not the first one either, but still, the disclosure of each and every one deserves attention.

[–] pHr34kY@lemmy.world 7 points 1 month ago

That flag. Ugh.

There was a time when by facebook wall was plastered with AI slop articles, and all of them had flags chucked in like this.

[–] truthfultemporarily@feddit.org 19 points 1 month ago (1 children)

Another case of: use an American router against the Chinese backdoor behind a Chinese router against the American backdoor.

(Or just do open source)

[–] AllNewTypeFace@leminal.space 11 points 1 month ago

throw an Indian router, an Israeli router and a Turkish router into the chain for extra security

[–] esc@piefed.social 10 points 1 month ago (1 children)

At least they should have good openwrt support!

[–] jobbies@lemmy.zip 3 points 1 month ago (1 children)

If its at the hardware level openwrt won't help.

[–] esc@piefed.social 7 points 1 month ago
[–] XLE@piefed.social 5 points 1 month ago (2 children)

oh COME ON. The last thing I needed in this jingoistic American economy was any reason to legitimize their crap

[–] A_norny_mousse@piefed.zip 12 points 1 month ago* (last edited 1 month ago) (1 children)

Do you mean, legitimize the USA being anti-China?

I think it's important to remember that the USA aren't the only bad player on the globe.
We can be against China without being pro MAGA.

[–] XLE@piefed.social 2 points 1 month ago* (last edited 1 month ago)

In this case, I was thinking of how this could be used to legitimize the decision a couple months ago to block the sale of all foreign-made routers.

(The decision is a terrible one, but I imagine MAGA people will use it to say "I told you so" while ignoring the fact that foreign brand Netgear got an exemption and at least temporary monopoly status.)

[–] NaibofTabr@infosec.pub 10 points 1 month ago* (last edited 1 month ago)

I mean... did you miss all the reporting on Salt Typhoon and Volt Typhoon?

[–] DoucheBagMcSwag@lemmy.dbzer0.com 4 points 1 month ago (2 children)
[–] 0x0@infosec.pub 19 points 1 month ago

Not necessarily. It would be entirely possible of the manufacturer to implement the original fw in a fused memory and restore from that. Basically persistent uefi malware. One would probably notice it, but i wouldnt bet my life on that being true forever with the rate our tech is advancing

[–] ReluctantMuskrat@lemmy.world 1 points 1 month ago (2 children)

It only solves it if you can install it on those routers. Can you??

[–] esc@piefed.social 2 points 1 month ago

I can, they are supported by owrt.

[–] RedGreenBlue@lemmy.zip 1 points 1 month ago

But can i put pfsense or something on it?

[–] AlteredEgo@lemmy.ml 0 points 1 month ago* (last edited 1 month ago) (2 children)

What are the chances this is some misguided customer support tool or someone screwing up?

I'd think if this was a deliberate attempt for hacking they'd at least have a proper authentication challenge. You wouldn't want your enemies to have access to your toys too. No matter how socialist you are haha.

[–] ayyy@sh.itjust.works 5 points 1 month ago (1 children)

.ml moment. The party asked you not to believe your own lying eyes, and you listened.

[–] AlteredEgo@lemmy.ml 3 points 1 month ago

Hanlon's razor

[–] Brosplosion@lemmy.zip 2 points 1 month ago

If it were, they wouldn't have tried to disguise it as a kworker