ENDLESSDOORS is an embedded remote-control backdoor found in firmware for numerous Zbtlink routers, including devices sold under white-label and related branding. It is implemented as a customized build of the open-source rctl remote-control utility, starts automatically at boot, runs with root privileges, and disguises itself as a Linux kworker process to blend into normal system activity. The implant is packaged into router firmware rather than delivered through a conventional intrusion chain, making it a factory-shipped or vendor-integrated implant rather than malware introduced post-deployment.
The backdoor initiates outbound command-and-control communications from the router to external infrastructure on a recurring basis. Its protocol lacks authentication, encryption, and meaningful client-server verification. After check-in, it accepts commands from the remote side and executes them as root, and it also supports opening an interactive root shell. Because the device phones home instead of exposing an inbound listener, affected routers can be remotely controlled even when placed behind NAT or common firewall configurations, provided they retain outbound connectivity.
ENDLESSDOORS has been associated with Zbtlink firmware images across more than 20 router models, and the issue has been tracked as CVE-2026-66747. Public reporting states that the implant was observed across multiple firmware generations and appears to be integrated by design. Zbtlink publicly disputed the backdoor characterization and described the functionality as intended for after-sales maintenance and debugging, but also suspended affected firmware downloads while preparing remediated releases. The malware primarily targets Linux-based network devices, especially cellular CPE and small-office or edge routers, and presents a high-risk foothold for persistent remote administration, post-exploitation, and potential downstream access into connected environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
La vulnérabilité est référencée CVE-2026-66747 . Les 20 modèles confirmés affectés incluent : CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, Z8102AX-2DSIM. | L’implant, nommé ENDLESSDOORS par VulnCheck, est une version personnalisée de rctl (remote control linux)... Il se déguise en processus kernel légitime (kworker)... Toute commande reçue est exécutée via popen() en root. La chaîne réservée rctlbash déclenche l’ouverture d’un shell interactif root sur le port 7001.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VulnCheck’s zero-day research team has disclosed ENDLESSDOORS, a command and control (C2) backdoor that is built into the firmware of routers made by Zbtlink.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
After that, anything the server sends is handed to popen() and executed as uid 0. There is no allow-list and no sandbox.
It's a component in the vendor’s product, started at boot by the vendor's own init script, shipped across twenty models and years of images
Because the device dials out, none of this requires the router to be reachable from the internet. There's no listening port to find and no inbound rule to punch through. The connection originates inside the network and traverses NAT and typical egress filtering
VulnCheck researchers found a backdoor baked into Zbtlink routers... Two processes named “kworker” were running as root... The researchers pointed out that twenty different router models carry the same backdoor, all of them starting it automatically at boot through an init script named skworker.
It's a component in the vendor’s product, started at boot by the vendor's own init script, shipped across twenty models and years of images
VulnCheck researchers found a backdoor baked into Zbtlink routers... Two processes named “kworker” were running as root... The researchers pointed out that twenty different router models carry the same backdoor, all of them starting it automatically at boot through an init script named skworker.
Two processes named “kworker” were running as root with real memory footprints, sitting right next to the legitimate kernel threads that share the same name... named to disappear into a crowd of legitimate ones.
Il se déguise en processus kernel légitime (kworker) dans la liste des processus, mais s’exécute en espace utilisateur avec les droits root.
The backdoor functions as a persistent communication mechanism, where the compromised router automatically beacons to a specific IP address and a Chinese-registered domain every 35 seconds. This automated outbound communication suggests a structured infrastructure designed for command-and-control capabilities
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
L’attaque fonctionne même derrière NAT et pare-feu car la connexion est initiée par le routeur.
whoever answers gains root-level access and a foothold to reach other systems on the same network
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor implant embedded in affected Zbtlink router firmware. It masquerades as a legitimate kworker process, persists via init.d, connects outbound to hardcoded C2 infrastructure over TCP/7000, executes arbitrary commands as root, and can expose an interactive root shell on port 7001.
Alleged built-in router backdoor/phone-home trojan feature in Zbtlink firmware that communicates with command-and-control servers via the rctl remote control Linux tool, using unencrypted communications that could be hijacked in transit.
A vendor-built backdoor implant in Zbtlink routers that disguises itself as userland 'kworker' processes, phones home to hardcoded servers, executes arbitrary commands as root via popen(), and can open an interactive root shell over a secondary connection.
Backdoor implanted in Zbtlink router firmware that starts at boot via an init.d script, masquerades as a Linux kworker process, connects to command-and-control infrastructure every 35 seconds, and allows unauthenticated remote command execution and interactive root shell access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.