hacker-news · Crawled Aug 6, 2026

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

13 IoCs
Read original article ↗

AI Summary

Zbtlink routers are shipped with a factory-implanted backdoor named ENDLESSDOORS, which establishes unauthenticated root shells by connecting to command-and-control servers. The backdoor, based on the 'rctl' tool, runs as a disguised kernel thread with root privileges and contacts C2 infrastructure every 35 seconds. It allows remote attackers to execute arbitrary commands or spawn interactive root shells without authentication, enabling full device takeover. The backdoor is present in at least 20 router models, all of which initiate connections to a shared set of C2 endpoints.

AI-extracted · verify before operational use

Indicators of Compromise 13 extracted

Type Value Detail
IP 47[.]107[.]224[.]89 Details →
Domain rbdg4nzqadui[.]wikaba[.]com Details →
IP 47[.]100[.]190[.]96 Details →
Domain zbtctl[.]epplink[.]net Details →
IP 45[.]32[.]81[.]152 Details →
Domain online-string[.]com Details →
IP 43[.]248[.]136[.]125 Details →
Filename /usr/sbin/kworker Details →
Filename /usr/lib/librctl.so Details →
Filename /etc/kworker.cfg Details →
Filename /etc/init.d/skworker Details →
GitHub Repo rctl Details →
GitHub User rctl Details →