this post was submitted on 10 Aug 2026
286 points (97.7% liked)

Technology

87279 readers
3513 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://mander.xyz/post/56484546

Here is the technical report: ENDLESSDOORS Is Phoning Home. Pick Up.

...

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.

They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The "phone home" implants have been codenamed ENDLESSDOORS.

"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. "Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server."

"The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell." Cybersecurity

The "kworker" worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that's configured to contact the following -

...

all 42 comments
sorted by: hot top controversial new old
[–] tinsuke@lemmy.world 65 points 1 week ago (3 children)

That ough to be one of the laziest genAI slop images for a "Chinese router with a backdoor".

Damn, it's bad.

[–] greyscale@lemmy.grey.ooo 31 points 1 week ago (1 children)

Yeah that one is fairly hideous. Why can't they just use a product shot?

[–] apftwb@lemmy.world 6 points 1 week ago (1 children)
[–] greyscale@lemmy.grey.ooo 1 points 6 days ago* (last edited 6 days ago)

therapist: the mimo spider can't get you

the mimo spider:

[–] pHr34kY@lemmy.world 7 points 1 week ago

That flag. Ugh.

There was a time when by facebook wall was plastered with AI slop articles, and all of them had flags chucked in like this.

[–] A_norny_mousse@piefed.zip 7 points 1 week ago* (last edited 1 week ago) (1 children)

A report of China obviously and illegally spying on large amounts of people (not only in the USA I might add), and that's the top comment?

[–] LincolnsDogFido@lemmy.zip 1 points 1 week ago (1 children)

I mean, it was assumed and mostly known that it was taking place already. Thats why the government tried to prevent them from being sold in the US. Did anyone really think they were going to give up on spying on world citizens when they were forced to sell TikTok?

[–] A_norny_mousse@piefed.zip 3 points 1 week ago

No. But a hardware backdoor is a big step from whatever TikTok is doing. And I know it's not the first one either, but still, the disclosure of each and every one deserves attention.

[–] Siegehammer85@lemmy.world 60 points 1 week ago (3 children)

Something the US has in common with China, they intercepted network gear and installed backdoors too while also demanding backdoors be installed in regular consumer devices. Plus the telecom/ISP secret surveillance rooms... Both countries governments are evil.

[–] partofthevoice@lemmy.zip 1 points 6 days ago

I guess the hack is to get one from the other country, because they can theoretically do less with the data.

[–] jobbies@lemmy.zip 42 points 1 week ago (3 children)

Every time I mention this being a risk with Chinese tech I get flamed.

The CCP effectively controls every chinese company. If they want backdoors, they get backdoors.

I say that as a centre-left European who has just as much criticism for American tech.

[–] Auli@lemmy.ca 1 points 6 days ago

And what is the difference between American companies?/ Microsoft has said they have to follow all requests from american government even of it goes against another countries laws. Like US asking for data in EU.

[–] village604@adultswim.fan 33 points 1 week ago (2 children)

They seem to think criticism of the CCP means support for the US fascists.

It's possible to hate both.

[–] jobbies@lemmy.zip 14 points 1 week ago (2 children)

Yeah. Or if you speak up about Gaza you're antisemetic. Or defend a Jewish person you're a fascist. Fucking hate the way things are.

[–] Greyghoster@aussie.zone 2 points 6 days ago

Usually but not always different people calling fascist and antisemitic. It’s really polarised society, media and politics.

[–] 0x0@infosec.pub 11 points 1 week ago* (last edited 1 week ago)

Pitching us against them has been the playbook of the epstein class since forever.

Bread and circus on repeat, our planet is a giant resort for the few and we are the serf~~vant~~s

Yeah, well said. I agree with you on this, I hate both

[–] Siegehammer85@lemmy.world -5 points 1 week ago (1 children)

Not sure why you're telling me that like especially as I'm essentially saying they are the opposite sides of the same fucked up coin. I'd say the fundamental difference is on the western side it's the child raping Epstein class is who is behind it all and who are actively working to make our lives more miserable driven by immense obsession of power and wealth. The Chinese side is more if defacto state operation which isn't benefiting a few greedy sickos but rather maintaining the whole status quo for the state. Neither should exists, both countries are a threat to the rest of the world, though the Americans have tilted the evil scale more towards themselves at this point in time. And in Europe we're now worried the US will flip a switch to cut us off from all cloud services too, besides spying on us, sabotage us and threatening invasion. China is somewhat less extreme now, but still undermining us and spying on is nonetheless. A swinging pendulum of who is more evil that I wish would turn into a wrecking ball and free us of this insanity.

[–] ayyy@sh.itjust.works 3 points 1 week ago (1 children)

You think they don’t have sicko billionaires in China? It’s a different country, not a different species.

[–] zbyte64@awful.systems 3 points 1 week ago (1 children)

They do have billionaires, but they aren't calling the shots. Just ask Jack Ma

[–] Buelldozer@lemmy.today 4 points 1 week ago* (last edited 1 week ago)

Everyone calling the shots in China is a Billionaire.

[–] hirihit640@sh.itjust.works 1 points 1 week ago (2 children)

At least in the west the companies can fight back, like Apple has done a few times. In China the government can force companies to do their bidding.

[–] Auli@lemmy.ca 2 points 6 days ago* (last edited 6 days ago) (1 children)

Apples fight back was for show. The FBI wanted it public and in the open. They throw their "morals" away as soon as it hits their bottom line. Look at China and how they handle Trump.

[–] hirihit640@sh.itjust.works 1 points 6 days ago* (last edited 6 days ago)

You're not contradicting what I said. Apple gets to choose whether they want to cooperate or not, based on their own "morals" and profit motives. Chinese companies don't get that choice

[–] explodicle@sh.itjust.works 2 points 1 week ago (1 children)

Which router companies fight back? Or computer hardware in general? Anybody with a warrant canary?

[–] hirihit640@sh.itjust.works 1 points 1 week ago

Apple makes computers? You can turn an Apple computer into a router in 10 minutes using docker

[–] truthfultemporarily@feddit.org 19 points 1 week ago (1 children)

Another case of: use an American router against the Chinese backdoor behind a Chinese router against the American backdoor.

(Or just do open source)

[–] AllNewTypeFace@leminal.space 11 points 1 week ago

throw an Indian router, an Israeli router and a Turkish router into the chain for extra security

[–] esc@piefed.social 10 points 1 week ago (1 children)

At least they should have good openwrt support!

[–] jobbies@lemmy.zip 4 points 1 week ago (1 children)

If its at the hardware level openwrt won't help.

[–] esc@piefed.social 5 points 1 week ago
[–] XLE@piefed.social 5 points 1 week ago (2 children)

oh COME ON. The last thing I needed in this jingoistic American economy was any reason to legitimize their crap

[–] A_norny_mousse@piefed.zip 13 points 1 week ago* (last edited 1 week ago) (1 children)

Do you mean, legitimize the USA being anti-China?

I think it's important to remember that the USA aren't the only bad player on the globe.
We can be against China without being pro MAGA.

[–] XLE@piefed.social 3 points 1 week ago* (last edited 1 week ago)

In this case, I was thinking of how this could be used to legitimize the decision a couple months ago to block the sale of all foreign-made routers.

(The decision is a terrible one, but I imagine MAGA people will use it to say "I told you so" while ignoring the fact that foreign brand Netgear got an exemption and at least temporary monopoly status.)

[–] NaibofTabr@infosec.pub 12 points 1 week ago* (last edited 1 week ago)

I mean... did you miss all the reporting on Salt Typhoon and Volt Typhoon?

[–] DoucheBagMcSwag@lemmy.dbzer0.com 3 points 1 week ago (2 children)
[–] 0x0@infosec.pub 17 points 1 week ago

Not necessarily. It would be entirely possible of the manufacturer to implement the original fw in a fused memory and restore from that. Basically persistent uefi malware. One would probably notice it, but i wouldnt bet my life on that being true forever with the rate our tech is advancing

[–] ReluctantMuskrat@lemmy.world 1 points 1 week ago (2 children)

It only solves it if you can install it on those routers. Can you??

[–] esc@piefed.social 2 points 1 week ago

I can, they are supported by owrt.

[–] RedGreenBlue@lemmy.zip 1 points 1 week ago

But can i put pfsense or something on it?