Overview
Security analysts at VulnCheck have discovered a hidden remote‑control implant inside more than 20 models of Zbtlink routers sold globally. The implant, named ENDLESSDOORS, launches at boot and grants attackers full administrative control, turning trusted network gateways into potential entry points for surveillance, lateral movement, and deeper compromise.
How the Backdoor Works
- Disguised process: ENDLESSDOORS masquerades as
kworker, a name normally associated with routine Linux activity. - Outbound connection: Instead of waiting for inbound requests, the implant calls out to external infrastructure, bypassing firewall rules and NAT.
- Command execution: Once registered with its server, the implant can run commands as root or provide an interactive shell.
- No user action required: Attackers only need to control or intercept the trusted destination domain.
Indicators of Compromise (IoCs)
- Domains:
zbtctl.epplink[.]net,online-string[.]com,rbdg4nzqadui[.]wikaba[.]com. - IPs:
47.100.190[.]96,45.32.81[.]152,43.248.136[.]125. - Files:
/usr/sbin/kworker,/usr/lib/librctl.so,/etc/kworker.cfg,/etc/init.d/skworker. - Ports: TCP/7000 (check‑in), TCP/7001 (interactive shell).
- Command string:
rctlbash.
Why It Matters
Routers sit between users and the internet, making them strategic footholds for attackers. A compromised router can:
- Inspect and manipulate traffic.
- Move deeper into local networks.
- Change settings or install further tools.
- Remain undetected for long periods due to outbound design.
What Owners Should Do Now
- Identify affected models: Check devices including CPE2801, WE‑series, WG‑series, and Z8102AX‑2DSIM.
- Look for suspicious processes: Unbracketed
kworkerrunning as root is a red flag. - Block destinations: Alert on outbound traffic to listed domains/IPs, especially on TCP ports 7000 and 7001.
- Replace compromised devices: Firmware cannot be trusted; replacement is safer than disabling scripts.
- Isolate if replacement is delayed: Place behind strict outbound controls and keep local networks separate.
- Preserve logs: Record model, firmware, process state, and network events before removal.
Expert in the Cloud Insight
The ENDLESSDOORS discovery highlights the supply chain risks of low‑cost networking gear. Unlike typical vulnerabilities, this implant is baked into firmware, requiring no user interaction. For defenders, the lesson is clear: trust must be verified at the hardware and firmware level, and unsupported devices should be treated as high‑risk infrastructure.
Leave a Reply