Hidden Surveillance Implants Found in Chinese-Made Routers Sold Worldwide
Security researchers from VulnCheck have uncovered three surveillance‑style implants hidden inside the firmware of routers manufactured by Chinese company ZBT and sold worldwide under many rebranded names. The ENDLESSDOORS implant was found in firmware for at least 20 ZBT models, including Z8102AX, WG3526, WE826‑T3‑DSIM, and numerous other cellular routers. Two additional implants, DARKLANTERN and SPEAKINGSTONE, were discovered in older firmware such as that of the ZBT‑WE826‑T2, also sold under brands like Deep Orange. DARKLANTERN exposes devices directly to the Internet via UDP port 9992, while SPEAKINGSTONE periodically beacons to ZBT’s command servers and enables credential theft, DNS hijacking, and remote command execution. VulnCheck’s sinkhole operation showed that hundreds of devices, mostly in China, were actively connecting to the command infrastructure, suggesting large‑scale domestic surveillance. Because ZBT hardware is widely resold under many brand names, users often do not know they are running ZBT firmware. The implants appear intentionally included rather than accidental vulnerabilities, and researchers warn that affected devices cannot be trusted even with firmware updates. For users of impacted models, the only reliable solution is full device replacement.
Read the full story on Tom’s Hardware →