ENDLESSDOORS is an embedded remote-control backdoor identified in firmware for more than 20 Zbtlink router models manufactured by Shenzhen Zhibotong Electronics, including devices distributed under Zbtlink, Wiflyer, ZBT, and other OEM or white-label brands. Tracked as CVE-2026-66747, it is a customized build of the open-source rctl remote-control utility. The implant starts automatically during device boot, runs in user space with root privileges, and masquerades as a Linux kernel worker process to reduce visibility. It persistently initiates outbound cleartext command-and-control communications, allowing it to operate through NAT and perimeter firewalls without requiring an inbound management interface. Its command channel lacks authentication and encryption; received commands are executed as root, and the implant can establish an interactive root shell. Consequently, an actor able to impersonate or intercept its command-and-control communications can take control of an affected router. Zbtlink characterized the functionality as an after-sales maintenance mechanism, while public technical analysis identified its presence across multiple production firmware images and models.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ENDLESSDOORS (CVE-2026-66747, CVSS 4.0 : 9.3) est un implant compilé dans chaque image firmware examinée par VulnCheck, couvrant plus de 20 modèles distincts sur au moins deux ans de releases. | ENDLESSDOORS (CVE-2026-66747) est un implant compilé dans chaque image firmware examinée... Il s’agit d’un build modifié de rctl.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VulnCheck’s zero-day research team has disclosed ENDLESSDOORS, a command and control (C2) backdoor that is built into the firmware of routers made by Zbtlink.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Because the device dials out, none of this requires the router to be reachable from the internet. There's no listening port to find and no inbound rule to punch through. The connection originates inside the network and traverses NAT and typical egress filtering
After that, anything the server sends is handed to popen() and executed as uid 0. There is no allow-list and no sandbox.
« Persiste via un script init (/etc/init.d/skworker) survivant aux redémarrages. »
Because the device dials out, none of this requires the router to be reachable from the internet. There's no listening port to find and no inbound rule to punch through. The connection originates inside the network and traverses NAT and typical egress filtering
« ENDLESSDOORS ... est un implant compilé dans chaque image firmware examinée ... couvrant plus de 20 modèles distincts. »
VulnCheck researchers found a backdoor baked into Zbtlink routers... Two processes named “kworker” were running as root... The researchers pointed out that twenty different router models carry the same backdoor, all of them starting it automatically at boot through an init script named skworker.
« Persiste via un script init (/etc/init.d/skworker) survivant aux redémarrages. »
VulnCheck researchers found a backdoor baked into Zbtlink routers... Two processes named “kworker” were running as root... The researchers pointed out that twenty different router models carry the same backdoor, all of them starting it automatically at boot through an init script named skworker.
It starts automatically at boot and disguises itself as a normal Linux kernel process called kworker.
« S’exécute en tant que processus root en espace utilisateur sous le nom kworker pour imiter les threads noyau Linux légitimes. »
„Die versteckt sich mit dem Namen ‚kworker‘ als Userland-Prozess mit root-Rechten und imitiert dadurch echte kworker-Prozesse.“
The hidden component disguises itself as kworker , a name normally associated with routine Linux activity.
The backdoor functions as a persistent communication mechanism, where the compromised router automatically beacons to a specific IP address and a Chinese-registered domain every 35 seconds. This automated outbound communication suggests a structured infrastructure designed for command-and-control capabilities
La liste TTP identifie « T1071.001 — Application Layer Protocol: Web Protocols (Command and Control) » ; l’implant balise vers des destinations C2 hardcodées toutes les 35 secondes.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously reported Zbtlink firmware implant/backdoor that establishes contact with remote command-and-control infrastructure and enables unauthenticated execution of commands with root privileges.
Factory-preinstalled persistent router-firmware backdoor that runs as root while masquerading as the Linux kworker process. It persists through an init script, beacons to hard-coded C2 infrastructure every 35 seconds, and permits unauthenticated root shell-command execution or an interactive reverse root shell.
Implant de firmware ZBT décrit comme un RAT. Le présent contenu ne fournit pas de détails techniques supplémentaires sur ses capacités.
A router-firmware remote-control implant that starts at boot while masquerading as the Linux kworker process. It periodically contacts a hard-coded C2 server without meaningful authentication or encryption, executes received commands as root, and can establish an interactive root shell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.