VulnCheck disclosed ENDLESSDOORS, a factory-shipped backdoor embedded in at least 20 Zbtlink router models and present across all 21 available firmware images. The implant runs at boot, phones home to multiple command-and-control endpoints, and can be hijacked to grant attackers a live root shell on affected devices. #ENDLESSDOORS #Zbtlink #rctl
Keypoints
- ENDLESSDOORS is a factory-shipped backdoor found in Zbtlink router firmware.
- The implant starts automatically and beacons to external C2 servers every 35 seconds.
- It disguises itself as a Linux kworker process while running with root privileges.
- Researchers traced the backdoor to an old GitHub tool called rctl.
- Affected users should check for skworker-related files and block the listed endpoints.
Read More: https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html