Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS CYBERSECURITY OPERATIONS PERIMETER ENDPOINT SECURITY NEWS Chinese Routers Sold Worldwide Contain Backdoors An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. Nate Nelson,Contributing Writer August 27, 2026 5 Min Read SOURCE: DEAGREEZ VIA GETTY IMAGES A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe. Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The Shenzhen-based 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.6 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions. On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT's most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years. Related:Exploited Zimbra Flaw Highlights Shrinking Window to Patch Backdoors in Chinese Tech Chinese backdoors in network technologies has always been something of a stereotype, but perhaps never been this blatant. Earlier this summer, Baines found a decade-old open source Linux remote control tool built into the router in his home office. "EndlessDoors," as it's called, was disguised as a kernel thread for ordinary system processing. When a router such as his was powered on, it would beacon out to a strange domain, passing through any number of firewalls — because the connection initiates out to the Internet, rather than in from it — to establish command-and-control (C2) communications. Whomever controlled that domain could have commanded the router with root-level privileges. They could have spied on Baines' Internet activity, stolen his credentials, or used it as an entry point into the rest of his network. EndlessDoors impacted dozens of router models. Baines's personal router was sold by Zbtlink, a ZBT brand. After discovering EndlessDoors, Baines went on Amazon and bought a different router from a different company, DeepOrange. The New York-based DeepOrange, like so many others, merely sells ZBT technology under its own brand name. Interestingly, its router didn't have EndlessDoors inside, but it did contain two other backdoors, which he named "SpeakingStone" and "DarkLantern." Upon further inspection, these appeared to be earlier versions of EndlessDoors, implemented in ZBT firmware around 2019. Countless Infected ZBT Routers Unlike the other two implants, DarkLantern is a listener. ZBT, or an attacker in possession of its C2 infrastructure, can initiate a connection into a DarkLantern-infected router. ZBT boxes are explicitly designed to allow traffic to the UDP port the malware listens for, making the task simple unless the device is otherwise protected by third-party firewalls. Related:N-able Bug Exposes Password Vault Master Keys In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online. According to Baines, 103 of those connections originated from the US, with most of the rest coming from Russia, Taiwan, China, Ukraine, and Israel. SpeakingStone is the more useful of the two since, like EndlessDoors, it initiates a connection out to its controlling domain. It first sends a variety of system data, including its GPS coordinates. It then accepts arbitrary system-level commands, plus specific malicious ones, such as the ability to perform Domain Name System (DNS) hijacking. Luckily, whoever designed SpeakingStone hadn't registered one of its C2 domains as of the time of the research, allowing Baines to grab and sinkhole it. He picked up 392 SpeakingStone connections to date, almost exclusively originating in China. DarkLantern and SpeakingStone infections likely number only in the hundreds, because those versions of the implant are outdated and associated with end-of-life hosts. By contrast, EndlessDoors affects all of ZBT's current firmware images. Related:'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture In trying to gauge the full blast radius of EndlessDoors, Baines laments, "the white-labeling and difficulty tracing things makes it really hard to say." He guesses that the number of infected devices numbers in the six figures. Defending Against Edge Device Implants Dark Reading contacted ZBT and DeepOrange for this story, but neither company had responded at press time. When Baines contacted the manufacturer, he recalls, "ZBT responded by shutting down all sales on Amazon and their website, and saying, 'We're going to fix this.' And they've released some firmware that removes the implant, and subsequently have allowed you to purchase their stuff off Amazon again. So last week I purchased one of their devices under the WiFlyer brand name, and it came totally unpatched with the implant on it." Since backdoored ZBT routers remain available today on marketplaces like Amazon and Alibaba, and they're sold under innocuous brand names, organizations need to proactively identify whether they've accidentally deployed Chinese spy tech. "There are two hardware MAC addresses that are specifically allocated to ZBT, so look those up and try to track those down," Baines advises. Besides that, he says, "the only thing I would do is unplug them and replace them." For some organizations, ripping and replacing routers won't be an easy task. One of the primary features ZBT specializes in is building 4G and 5G connectivity into its products, Baines notes, "which means they're deployed in places that are more remote and not necessarily easy to get to. An example is an oil pipeline: you want monitoring software on your pipeline, you need to get Internet connectivity so that telemetry can get shipped back. This is a good option because it will just connect to a cell service. But getting a human out there to both identify this is a ZBT system, and then replacing it, is non-trivial." At the end of the day, Baines says, "You have to really know the brand names that you're interacting with very well. I hate to shell for [any specific company], but maybe just stick with the Ciscos and Ubiquitis of the world. They're tried. True. We trust them." About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember More Webinars You May Also Like VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 VULNERABILITIES & THREATS 'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails by Nate Nelson SEP 19, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Om