Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-06 ยท updated: 2026-08-06 ยท tags: [incident, supply-chain, backdoor, router, iot, china] ยท confidence: high ยท affected_sectors: [technology, retail, government] ยท au_impact: true

Chinese-Made Zbtlink Routers Ship With BACKDOOR (ENDLESSDOORS)

Cybersecurity researchers disclosed a factory-shipped backdoor implanted in at least 20 Chinese router models from Zbtlink, catalogued by VulnCheck as ENDLESSDOORS. The implant appears in all 21 firmware images available spanning more than two years, starts automatically and attempts to beacon to Chinese C2 infrastructure as often as every 35 seconds, masquerading as a kernel thread while running as a privileged userland process (a tool called "rctl").

Attribute Detail
Scope 20+ Zbtlink router models
Catalogue VulnCheck "ENDLESSDOORS"
Persistence Present in all 21 firmware images over 2+ years
Behaviour Auto-start; beacons to Chinese C2 every ~35s; masquerades as kernel thread (userland "rctl")
Source VulnCheck (via The Hacker News) โ€” Tier 2/4

A factory-shipped, persistent supply-chain backdoor in consumer/edge routers โ€” an IoT security and national-security concern for Five Eyes partners.

Related Pages

Source