Головні звуки українського ІТ. Вгадаєш всі? 👉

Researchers have found three backdoors in ZBT routers, which are sold worldwide under other brands. How dangerous are they?

Cybersecurity researchers at VulnCheck have found several backdoors in the firmware of routers from the Chinese company Shenzhen Zhibotong Electronics, or ZBT. The company manufactures devices that are then sold around the world under other brands. So the owner of such a router may not even know who actually manufactured it. They also found one of the infected devices in Ukraine.

Leave a comment
Researchers have found three backdoors in ZBT routers, which are sold worldwide under other brands. How dangerous are they?

Cybersecurity researchers at VulnCheck have found several backdoors in the firmware of routers from the Chinese company Shenzhen Zhibotong Electronics, or ZBT. The company manufactures devices that are then sold around the world under other brands. So the owner of such a router may not even know who actually manufactured it. They also found one of the infected devices in Ukraine.

This was reported by researchers from VulnCheck.

The researchers first found the ENDLESSDOORS backdoor. It automatically starts with the router, disguises itself as a regular system process, and establishes a connection to the control server.

The server operator can then execute commands on the router with root privileges — that is, with virtually the maximum level of access to the system. According to VulnCheck, this potentially allows them to monitor traffic, steal credentials, or use the router as an entry point to other devices on the network.

And then VulnCheck CTO Jacob Baines ordered another router on Amazon — now under the Deep Orange brand. It turned out that it was actually the ZBT model, only with a different name. ENDLESSDOORS was not in the old firmware, but two more backdoors were found inside — DARKLANTERN and SPEAKINGSTONE. VulnCheck considers them to be early versions of the same remote access mechanism.

DARKLANTERN allows commands to be sent to the router over the Internet. It receives them on UDP port 9992, which is not blocked by the router's firewall. The backdoor is supposed to check the received commands before executing them, but researchers have found that these checks are easy to bypass. As a result, an unauthorized user can execute arbitrary commands on the device with root privileges.

But SPEAKINGSTONE works differently. The router itself regularly contacts the management server. Along with the request, it can transmit the device model and firmware version, MAC address, Wi-Fi network name, local IP address, operating time and even GPS coordinates. In response, the server can send it commands. Among the possibilities are changing DNS, obtaining PPPoE data and opening a reverse SSH tunnel. This makes it possible to create a channel for remote access to the device.

In addition, one of the backup SPEAKINGSTONE control domains turned out to be unregistered, so VulnCheck bought it itself. On it, the researchers launched their own server, to which routers with a backdoor began to automatically connect instead of the control server. 392 routers connected to it.

It’s much harder to figure out how many of these devices are actually operating in the world. ZBT manufactures the equipment, and other companies slap their logos on it and sell it as their own product. The researchers tracked ZBT equipment in the United States, Canada, Australia, the Philippines, Germany, and other countries. They named WiFlyer, Deep Orange, KuWFi, and CroSkylink among the brands and vendors that used the company’s platforms.

But this does not mean that every ZBT-based router has a backdoor. Some vendors install their own firmware. For example, no such components were found in the Canadian MOFI device tested by VulnCheck.

After VulnCheck was first published, Zbtlink temporarily stopped selling some routers and removed the corresponding firmware from its website. The company explained that the remote access feature was created for technical support and should only be used with the customer's permission.

Previously, dev.ua wrote that hackers linked to China had seized more than 50,000 Asus routers around the world, including in Ukraine, and used them as a hidden infrastructure for cyberespionage.

Russians hacked Ukrainians' home and office Wi-Fi routers and used them to intercept passwords and emails. SBU FBI and EU counterintelligence hacked GRU network
Russians hacked Ukrainians' home and office Wi-Fi routers and used them to intercept passwords and emails. SBU, FBI, and EU counterintelligence hacked GRU network
On the topic
Russians hacked Ukrainians' home and office Wi-Fi routers and used them to intercept passwords and emails. SBU, FBI, and EU counterintelligence hacked GRU network
Slovakia discovered Russian backdoors in speed cameras: the country's Interior Ministry initially denied everything
Slovakia discovered Russian backdoors in speed cameras: the country's Interior Ministry initially denied everything
On the topic
Slovakia discovered Russian backdoors in speed cameras: the country's Interior Ministry initially denied everything
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».
6
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
4 comments
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
4 comments
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
3 comments

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.