Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line... Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root. | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Its status lights blink and twinkle as it continuously attempts to reach a command and control server on the internet... kworker on the AX3000 is a customized version of rctl, and it’s been configured to phone home to 47.107.224[.]89 and rbdg4nzqadui[.]wikaba[.]com. | The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An embedded remote-control implant/backdoor in Zbtlink router firmware that runs as root at boot, disguises itself as kworker, phones home to a hardcoded C2 over unauthenticated cleartext TCP, executes received commands via popen() as uid 0, and supports an interactive root shell via the rctlbash command.
A preinstalled router implant/backdoor embedded in Zbtlink firmware that disguises itself as 'kworker', phones home to hardcoded C2 infrastructure, executes arbitrary commands as root via popen(), and can spawn an interactive reverse shell using the 'rctlbash' command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.