Posted on 08/31/2026 8:28:06 PM PDT by SeekAndFind
Cybersecurity researchers have found surveillance backdoors in Chinese carrier routers made by Zbtlink and the same software in a different Zbtlink-made router sold through Amazon.
Chinese law requires telecom and internet companies to provide technical assistance to police and state-security agencies.
In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.
The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.
The researchers then found both programs operating on routers already connected to the internet.
The findings expand VulnCheck’s Aug. 5 investigation, which involved a different Zbtlink backdoor, named ENDLESSDOORS, found across more than 20 router models sold worldwide.
The newly discovered backdoors are older. VulnCheck found them in router software dating to 2019, years before ENDLESSDOORS was disclosed.
Speakingstone was not simply dormant code sitting inside old router software. It was still running.
VulnCheck researcher Jacob Baines registered an abandoned internet address that Speakingstone had been programmed to contact. Routers began sending information to it almost immediately, according to VulnCheck.
By Aug. 21, 392 routers had contacted the researchers. Of those, 390 were in China, and 83 percent were connected through China Mobile. Another 304 used Wi-Fi names beginning with “CMCC,” China Mobile’s commonly used abbreviation. Baines also detailed the figures in an Aug. 27 post on X.
Most—363 of the 392 routers—were the same model running the same software version.
Baines said the pattern appeared to be a large deployment of routers provided by a telecommunications carrier to customers inside China. VulnCheck described it as “domestic Chinese surveillance technology.”
The 392 routers may represent only part of the deployment. VulnCheck counted devices trying to reach the abandoned backup address; routers already communicating with the main server would not have appeared in that count, Baines explained.
Speakingstone gave whoever controlled its remote server broad access to an affected router.
VulnCheck said an operator could collect information about the device, obtain the credentials it used to connect to the internet, redirect internet traffic, and take control of the router. Its security advisory also says the software can open another path for remote access.
Baines described Speakingstone in his Aug. 27 post as software that “phones home to ZBT infrastructure and supports remote surveillance.” ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.
The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.
Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.
Jeremiah Ford, a senior cloud support engineer with 25 years of experience in information technology, said the most serious issue was that the routers exposed administrator-level access directly to the public internet.
“This is the biggest problem,” Ford said.
He said full control of a router could also give an attacker access to other devices on the same network. Ford called the scale of the exposure significant, pointing to VulnCheck’s finding that every detected Darklantern device offered administrator-level access without authentication.
“This is huge,” he said. “And based on the numbers of devices affected by this, the scale could have been huge, if it went undetected.”
The U.S. exposure extended beyond the single router the researchers bought on Amazon.
VulnCheck found 203 routers running Darklantern that were directly reachable from the internet across 22 countries. More than half—103—were in the United States. The devices identified themselves as 16 different ZBT router models.
The researchers traced the device to Zbtlink. That device also contained Darklantern.
Zbtlink manufactures equipment that other companies can sell under different names, meaning buyers may not see the Zbtlink name on the product.
VulnCheck traced Zbtlink hardware to brands and products sold in multiple countries, including the United States, but cautioned that not every product using Zbtlink hardware necessarily contains the backdoors.
The discovery comes in a country where telecom and internet companies are legally required to assist police and state-security agencies.
China’s Cybersecurity Law requires network operators to provide technical support and assistance for national-security work and criminal investigations.
Article 18 of China’s Counter-Terrorism Law requires telecommunications and internet providers to give public-security and state-security agencies technical interfaces, decryption, and other technical assistance for terrorism investigations.
Accounts of police access to telecommunications systems date back decades.
Minghui, a U.S.-based website that documents the persecution of Falun Gong practitioners and publishes first-hand accounts from China, has documented cases in which practitioners were detained after authorities monitored their telephone or internet communications.
In a 2006 article, Minghui described special police-monitoring interfaces connecting Chinese telecommunications equipment with public-security systems. The account said police could use the systems to trace calls and identify people contacted by someone under surveillance.
The article concerned an earlier generation of telecommunications equipment, two decades before the newly reported Zbtlink backdoors.
The findings were issued months after the Federal Communications Commission (FCC) moved to restrict approval of new foreign-made consumer routers over national security concerns.
On March 23, the FCC added foreign-produced consumer-grade routers to its Covered List following a national security determination by executive branch agencies. The action prevents approval of new covered router models unless an exemption applies; equipment already authorized can remain on the market.
The FCC said malicious actors had exploited weaknesses in foreign-made routers to attack U.S. households, enable espionage, and disrupt networks. It also said foreign-made routers were involved in the Volt Typhoon, Flax Typhoon, and Salt Typhoon cyber campaigns targeting U.S. infrastructure.
As of Aug. 28, VulnCheck’s advisories did not list patched software versions for Speakingstone or Darklantern, leaving owners of affected routers without a published fix.
This has been a known issue for over a decade.
“Refurbished” Cisco gear is notorious for it.
L
How do I know if I have a Chicom router? Is there a list somewhere?
IT found a Cisco card trying to phone home - didn’t work, network was air-gapped.
Got a spare machine laying around - thinking OpenBSD router or replace my current TP-Link router. It’s an older unit.
How do I know if I have a Chicom router? Is there a list somewhere?
Check the tag with the serial number/password/ssid on it.
Ping.
Switch to Starlink - no worries.
Switch to Starlink - no worries.
****************************
Got a nephew on Starlink. He’s very satisfied with his hookup.
Remember, any Chinese company of any size, and most certainly in tech, for export - has a required Communist Party apparatus and Party head within it.
Chances are you’re still ok if you only go to sites starting with “https”—until the Chinese figure out how to quickly decode encrypted traffic that gets copied and forwarded to the China mothership. But they could still take over the router with their hacked factory firmware and at least cut you off if they wanted to…. It’s a jungle out there!
Count two; i have had it for about 6 months and cannot see myself ever going back to cable. Was a bit leery about satellite wifi as a prior experience with DirecTV internet was ... less than satisfactory but am very happy with it. It is leaps and bounds beyond anything else (including a T1 line I had) I have ever used.
All of your advice sounds great... but is actually incorrect except for saying not to totally trust anything and to some extent the Starlink comment. Realtime https decryption has been a thing for many decades.... We do it at work and have since the mid 2000’s. Hardware can bypass OpenWRT easily (and does). The simple truth is, there is absolutely nothing you can do to obscure yourself from nation states and telecom.
List of Equipment and Services Covered By Section 2 of The Secure Networks Act
We reference this often for customers in cybersecurity-related incidents.
Please, I implore all of you, if you are using TPLink, Huawei, ZTE... STOP USING THEM! I can't stress enough how absurdly easy it is to compromise them, even if their firmware is patched current. And this doesn't mean just the Chicoms. Threat actors are leveraging these backdoors to gain access to home networks. You will never know it's happening.
Ubiquiti, an American company, has a line of consumer network equipment in their Amplifi line that I can't recommend enough. It's very quick and easy to setup, and you can rest a little easier that you're in good hands. Might be a slightly higher price tag for entry, but the hardware is approved for use by the FCC.
Unfortunately you’re slightly misinformed. OpenWRT allows you to change the operating system on the router, but it doesn’t change the hardware itself insomuch as the Chicoms are embedding microcontrollers on the router mainboards with wide open backdoors. You can’t even detect them with open source scanning utilities such as NMAP, but they’re there. Oftentimes it’s a small component the size of a grain of rice, and some reverse engineers have tried removing the module itself; but it bricks the device.
Realtime HTTPS decryption requires a man-in-the-middle, oftentimes relying on SSL-interception certificates that act as intermediary certificate authorities. They take the traffic, assess it, and re-encrypt it using the subCA certificate. This isn’t like typical brute force decryption, it’s just a legitimate man-in-the-middle, and yes, there are hardware vendors out there that will package SSL interception capabilities into the router firmware.
Me too. Had Starlink since it was available and love it.
Click Start Button in lower left corner, type in ‘Router’ in DOS Box at bottom, get name from one of the files, do a Google Search for it.
I tried a decently spec’d Android tablet from China ($69). Works great. Then I paused when I was about to enter gmail credentials...then realized just how much I shouldn’t trust the device. It’s now used purely for anonymous random web browsing.
One could easily argue any personal data entered is worth far more than the purchase price.
I just wanted to keep it a paragraph or two and suggest something other than doing nothing and leaving a known suspect OS on the box if they wanted to keep and use it. At the very least replace the possibly suspect OS as a precaution. Not surprised if https/TLS is done but improving encryption has always been a moving target and new TLS versions might keep an organization ahead of its adversaries. Again, better than doing nothing.
My former office used to “gift” had Cisco gear to certain governments and then watch their traffic once placed online. That mod led to the “law enforcement” versions of IOS. I know hardware mods can’t usually be fixed or bypassed and have to be lived with the best that one can. I once had to deal with the mentality that it would be better to place 15000 almost gifted Lenovo workstations with possibly suspect BIOSs on an unclassified network with Internet access than on an isolated classified network. I didn’t like using the things at all but given the lousy, politically-motivated decision to use them anyway, tried to give the best possible answer under the circumstances. Whether it worked or not remained to be seen assuming the class network (that I had no control over) was actually unable to send routable packets onto the Internet. Unroutable private addressing on the class network helped but it was better for my future than telling them to not bother doing anything because they’re screwed, put the WSs on the unclass net and then having the entirety of a bigwig’s supposedly unclass mailbox (the aggregate of which was really not unclass but they didn’t want to admit that…) transmitted to China over the Internet. Some bosses really just don’t want to hear the truth.
President Trump needs to bar Chinese goods from entering this country and nationalize all of the farmland and food processing facilities they own inside the USA. They are at war with us and we continue to capitulate to them.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.