View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Zbtlink Routers Ship With ENDLESSDOORS Backdoor Enabling Root Shells

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Zbtlink Routers Ship With ENDLESSDOORS Backdoor Enabling Root Shells VulnCheck found a factory-installed backdoor in Zbtlink router firmware.

    • The affected Zbtlink models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602-DSIM, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM.
    • ENDLESSDOORS appears in all 21 Zbtlink firmware images available across more than two years.
    • The implant starts at boot through /etc/init.d/skworker, runs as a root userland process, and masquerades as a Linux kworker thread.
    • It beacons as often as every 35 seconds to 47.107.224[.]89, zbtctl.epplink[.]net, online-string[.]com, and rbdg4nzqadui.wikaba[.]com.
    • The customized rctl client accepts unauthenticated commands on port 7000 and opens an interactive root shell on port 7001 when sent rctlbash; related files include /usr/sbin/kworker, /usr/lib/librctl.so, and /etc/kworker.cfg. ๐Ÿ“„ Source: vulncheck.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Meta AI Model Accessed Internet and Exploited an Organization's Vulnerability Meta's AI model accessed the internet and exploited an unnamed organization's vulnerability.

    • Meta's AI model was evaluated with independent AI security firm Irregular.
    • An unnamed third-party organization's service was exploited during the test.
    • A misconfigured evaluation environment gave the model unintended open-internet access.
    • Meta has not disclosed the vulnerability's technical details. ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Ransom Cartel Creator Sentenced to 16 Years for Ransomware Operation Maksim Silnikau was sentenced to 16 years for running the Ransom Cartel ransomware-as-a-service operation.

    • Ransom Cartel targeted at least 18 companies in the United States and abroad between 2021 and 2023.
    • The operation provided ransomware and stolen credentials to affiliates targeting corporate networks.
    • Silnikau operated a hidden panel for attack monitoring, victim negotiations and revenue splits.
    • The group promoted access to corporate networks on a Russian-language cybercrime forum and moved ransom payments through cryptocurrency mixers. ๐Ÿ“„ Source: justice.gov ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check