hacker-news · Crawled Aug 6, 2026
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
13 IoCs
Read original article ↗
AI Summary
Zbtlink routers are shipped with a factory-implanted backdoor named ENDLESSDOORS, which establishes unauthenticated root shells by connecting to command-and-control servers. The backdoor, based on the 'rctl' tool, runs as a disguised kernel thread with root privileges and contacts C2 infrastructure every 35 seconds. It allows remote attackers to execute arbitrary commands or spawn interactive root shells without authentication, enabling full device takeover. The backdoor is present in at least 20 router models, all of which initiate connections to a shared set of C2 endpoints.
AI-extracted · verify before operational use
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 47[.]107[.]224[.]89 | Details → |
| Domain | rbdg4nzqadui[.]wikaba[.]com | Details → |
| IP | 47[.]100[.]190[.]96 | Details → |
| Domain | zbtctl[.]epplink[.]net | Details → |
| IP | 45[.]32[.]81[.]152 | Details → |
| Domain | online-string[.]com | Details → |
| IP | 43[.]248[.]136[.]125 | Details → |
| Filename | /usr/sbin/kworker | Details → |
| Filename | /usr/lib/librctl.so | Details → |
| Filename | /etc/kworker.cfg | Details → |
| Filename | /etc/init.d/skworker | Details → |
| GitHub Repo | rctl | Details → |
| GitHub User | rctl | Details → |