Surveillance Implants Found in Zbtlink Routers Sold Globally
Security researchers uncover three firmware-level backdoors allowing unauthorized root access and data exfiltration across 22 countries.
Security researchers have discovered three distinct surveillance implants embedded in the firmware of Chinese-made Zbtlink routers sold worldwide. The discovery reveals a systemic vulnerability in networking hardware that allows unauthorized actors to bypass security and exfiltrate data from affected networks.
According to research from VulnCheck, the three implants—identified as DARKLANTERN, SPEAKINGSTONE, and ENDLESSDOORS—are integrated directly into the device firmware. This means the vulnerabilities are present before the hardware ever reaches the consumer. The implants provide various levels of unauthorized access; specifically, DARKLANTERN allows for an unauthenticated root shell, while SPEAKINGSTONE and ENDLESSDOORS feature "phone-home" capabilities that enable remote command execution and data exfiltration. The impact is global, with exposed devices already detected across 22 different countries.
The Supply Chain Risk
This discovery arrives during a period of heightened global scrutiny regarding networking hardware manufactured in China. Several Western governments have already moved to restrict the use of specific Chinese brands within critical infrastructure, citing persistent concerns over state-sponsored espionage and the integrity of the hardware supply chain. The Zbtlink findings provide a concrete example of how firmware-level modifications can be used to create persistent access points that are invisible to the end user.
Why Firmware Implants Matter
Because these implants reside at the firmware level, they operate beneath the operating system of connected devices. Traditional security software and antivirus tools running on laptops or servers cannot detect these breaches because the compromise occurs at the gateway of the network. This grants attackers persistent, invisible access to all traffic passing through the router, potentially compromising sensitive corporate secrets and personal data on a global scale without triggering standard network alarms.
What's Next
Industry analysts and security teams are now tasked with identifying the full scale of Zbtlink's market penetration to determine how many networks remain vulnerable. While the technical nature of the implants has been confirmed, the specific actors behind the development of DARKLANTERN, SPEAKINGSTONE, and ENDLESSDOORS remain a primary point of investigation. Users of affected hardware are encouraged to monitor for firmware updates or replace compromised gateways to secure their network perimeter.