Skip to content
Chinese Routers Sold Worldwide Contain Backdoors

Chinese Routers Sold Worldwide Contain Backdoors

Darkreading •Nate Nelson • August 27, 2026

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.

Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The Shenzhen-based 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.6 million units . Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.

On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT's most updated router firmware contains a root-level backdoor . After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.

Chinese backdoors in network technologies has always been something of a stereotype, but perhaps never been this blatant.

Earlier this summer, Baines found a decade-old open source Linux remote control tool built into the router in his office. "EndlessDoors," as it's called, was disguised as a kernel thread for ordinary system processing.

When a router such as his was powered on, it would beacon out to a strange domain, passing through any number of firewalls — because the connection initiates out to the Internet, rather than in from it — to establish command-and-control (C2) communications. Whomever controlled that domain could have commanded the router with root-level privileges. They could have spied on Baines' Internet activity, stolen his credentials, or used it as an entry point into the rest of his network. EndlessDoors impacted dozens of router models.

Baines's personal router was sold by Zbtlink, a ZBT brand. After discovering EndlessDoors, Baines went on Amazon and bought a different router from a different company, DeepOrange. The New York-based DeepOrange, like so many others, merely sells ZBT technology under its own brand name.

Interestingly, its router didn't have EndlessDoors inside, but it did contain two other backdoors, which he named "SpeakingStone" and "DarkLantern." Upon further inspection, these appeared to be earlier versions of EndlessDoors, implemented in ZBT firmware around 2019.

Unlike the other two implants, DarkLantern is a listener. ZBT, or an attacker in possession of its C2 infrastructure, can initiate a connection into a DarkLantern-infected router. ZBT boxes are explicitly designed to allow traffic to the UDP port the malware listens for, making the task simple unless the device is otherwise protected by third-party firewalls.

In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online. According to Baines, 103 of those connections originated from the US, with most of the rest coming from Russia, Taiwan, China, Ukraine, and Israel.

SpeakingStone is the more useful of the two since, like EndlessDoors, it initiates a connection out to its controlling domain. It first sends a variety of system data, including its GPS coordinates. It then accepts arbitrary system-level commands, plus specific malicious ones, such as the ability to perform Domain Name System (DNS) hijacking .

Luckily, whoever designed SpeakingStone hadn't registered one of its C2 domains as of the time of the research, allowing Baines to grab and sinkhole it. He picked up 392 SpeakingStone connections to date, almost exclusively originating in China.

DarkLantern and SpeakingStone infections likely number only in the hundreds, because those versions of the implant are outdated and associated with end-of-life hosts. By contrast, EndlessDoors affects all of ZBT's current firmware images.

In trying to gauge the full blast radius of EndlessDoors, Baines laments, "the white-labeling and difficulty tracing things makes it really hard to say." He guesses that the number of infected devices numbers in the six figures.

Dark Reading contacted ZBT and DeepOrange for this story, but neither company had responded at press time.

When Baines contacted the manufacturer, he recalls, "ZBT responded by shutting down all sales on Amazon and their website, and saying, 'We're going to fix this.' And they've released some firmware that removes the implant, and subsequently have allowed you to purchase their stuff off Amazon again. So last week I purchased one of their devices under the WiFlyer brand name, and it came totally unpatched with the implant on it."

Since backdoored ZBT routers remain available today on marketplaces like Amazon and Alibaba, and they're sold under innocuous brand names, organizations need to proactively identify whether they've accidentally deployed Chinese spy tech.

"There are two hardware MAC addresses that are specifically allocated to ZBT, so look those up and try to track those down," Baines advises. Besides that, he says, "the only thing I would do is unplug them and replace them."

For some organizations, ripping and replacing routers won't be an easy task. One of the primary features ZBT specializes in is building 4G and 5G connectivity into its products, Baines notes, "which means they're deployed in places that are more remote and not necessarily easy to get to. An example is an oil pipeline: you want monitoring software on your pipeline, you need to get Internet connectivity so that telemetry can get shipped back. This is a good option because it will just connect to a cell service. But getting a human out there to both identify this is a ZBT system, and then replacing it, is non-trivial."

At the end of the day, Baines says, "You have to really know the brand names that you're interacting with very well. I hate to shell for [any specific company], but maybe just stick with the Ciscos and Ubiquitis of the world. They're tried. True. We trust them."

Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.

He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.

He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Cloud Incident Response: Forensics in Distributed Environments

Beyond the Login: Key Considerations for Evaluating Identity Security

SASE Pivot and Trends 2026: A Gartner Keynote

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember