this post was submitted on 10 Aug 2026
286 points (97.7% liked)

Technology

87315 readers
3163 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://mander.xyz/post/56484546

Here is the technical report: ENDLESSDOORS Is Phoning Home. Pick Up.

...

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS.

"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. "Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server."

"The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell." Cybersecurity

The "kworker" worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that's configured to contact the following -

...

you are viewing a single comment's thread
view the rest of the comments
[–] Siegehammer85@lemmy.world -5 points 1 week ago (1 children)

Not sure why you're telling me that like especially as I'm essentially saying they are the opposite sides of the same fucked up coin. I'd say the fundamental difference is on the western side it's the child raping Epstein class is who is behind it all and who are actively working to make our lives more miserable driven by immense obsession of power and wealth. The Chinese side is more if defacto state operation which isn't benefiting a few greedy sickos but rather maintaining the whole status quo for the state. Neither should exists, both countries are a threat to the rest of the world, though the Americans have tilted the evil scale more towards themselves at this point in time. And in Europe we're now worried the US will flip a switch to cut us off from all cloud services too, besides spying on us, sabotage us and threatening invasion. China is somewhat less extreme now, but still undermining us and spying on is nonetheless. A swinging pendulum of who is more evil that I wish would turn into a wrecking ball and free us of this insanity.

[–] ayyy@sh.itjust.works 3 points 1 week ago (1 children)

You think they don’t have sicko billionaires in China? It’s a different country, not a different species.

[–] zbyte64@awful.systems 3 points 1 week ago (1 children)

They do have billionaires, but they aren't calling the shots. Just ask Jack Ma

[–] Buelldozer@lemmy.today 4 points 1 week ago* (last edited 1 week ago)

Everyone calling the shots in China is a Billionaire.