Backdoors Found in ZBT Routers Sold Globally

Backdoors Found in ZBT Routers Sold Globally

First seen 27 Aug 2026, 20:19 UTC Darkreadingwww.vulncheck.comwww.techtarget.com 64.2

Article Content

Browse articles
ThreatCluster

ZBT routers, widely sold under various brands, have been found to contain multiple backdoors, including 'SpeakingStone' and 'DarkLantern'. These implants allow unauthorized remote access and command execution. The vulnerabilities were discovered by Jacob Baines, CTO of VulnCheck, who identified that ZBT routers beacon to a compromised domain upon activation. The backdoors are designed to bypass firewalls, making them particularly dangerous. The routers are sold in numerous countries, including the US, Canada, and Australia, with ZBT's annual output estimated at 3.6 million units. The issue affects a broad range of models and poses a significant risk to users' networks. The discovery has prompted urgent calls for users to secure their devices. As of now, the extent of exploitation remains unclear.

Key Points: • ZBT routers contain multiple backdoors, including 'SpeakingStone' and 'DarkLantern'. • The backdoors allow remote command execution and bypass firewall protections. • ZBT's routers are sold globally, affecting millions of users.

Timeline

2026-08-06
Backdoor discovery announced
Jacob Baines revealed ZBT's router firmware contains a root-level backdoor named 'EndlessDoors'.
Darkreading
2026-08-27
Further implants identified
Baines discovered two additional backdoors, 'SpeakingStone' and 'DarkLantern', in a different ZBT router model.
VulnCheck
2026-08-27
Global impact assessment
ZBT routers are reported to be sold in over 50 countries, affecting millions of devices worldwide.
Darkreading