Cybersecurity researchers have found surveillance backdoors in Chinese carrier routers made by Zbtlink and the same software in a different Zbtlink-made router sold through Amazon.
Chinese law requires telecom and internet companies to provide technical assistance to police and state-security agencies.
In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.
The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.
The researchers then found both programs operating on routers already connected to the internet.
The findings expand VulnCheck’s Aug. 5 investigation, which involved a different Zbtlink backdoor, named ENDLESSDOORS, found across more than 20 router models sold worldwide.
The newly discovered backdoors are older. VulnCheck found them in router software dating to 2019, years before ENDLESSDOORS was disclosed.
Speakingstone was not simply dormant code sitting inside old router software. It was still running.
VulnCheck researcher Jacob Baines registered an abandoned internet address that Speakingstone had been programmed to contact. Routers began sending information to it almost immediately, according to VulnCheck.
By Aug. 21, 392 routers had contacted the researchers. Of those, 390 were in China, and 83 percent were connected through China Mobile. Another 304 used Wi-Fi names beginning with “CMCC,” China Mobile’s commonly used abbreviation. Baines also detailed the figures in an Aug. 27 post on X.
Most—363 of the 392 routers—were the same model running the same software version.
Baines said the pattern appeared to be a large deployment of routers provided by a telecommunications carrier to customers inside China. VulnCheck described it as “domestic Chinese surveillance technology.”
The 392 routers may represent only part of the deployment. VulnCheck counted devices trying to reach the abandoned backup address; routers already communicating with the main server would not have appeared in that count, Baines explained.
Backdoor Could Redirect Traffic, Steal Credentials
Speakingstone gave whoever controlled its remote server broad access to an affected router.
VulnCheck said an operator could collect information about the device, obtain the credentials it used to connect to the internet, redirect internet traffic, and take control of the router. Its security advisory also says the software can open another path for remote access.
Baines described Speakingstone in his Aug. 27 post as software that “phones home to ZBT infrastructure and supports remote surveillance.” ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.
The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.
Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.
The U.S. exposure extended beyond the single router the researchers bought on Amazon.
VulnCheck found 203 routers running Darklantern that were directly reachable from the internet across 22 countries. More than half—103—were in the United States. The devices identified themselves as 16 different ZBT router models.
Zbtlink Sold Under Other Brands
The same Speakingstone software found on the China Mobile-linked routers was present in the Deep Orange router VulnCheck bought through Amazon in the United States.
The researchers traced the device to Zbtlink. That device also contained Darklantern.
Zbtlink manufactures equipment that other companies can sell under different names, meaning buyers may not see the Zbtlink name on the product.
VulnCheck traced Zbtlink hardware to brands and products sold in multiple countries, including the United States, but cautioned that not every product using Zbtlink hardware necessarily contains the backdoors.
The discovery comes in a country where telecom and internet companies are legally required to assist police and state-security agencies.
China’s Cybersecurity Law requires network operators to provide technical support and assistance for national-security work and criminal investigations.
Article 18 of China’s Counter-Terrorism Law requires telecommunications and internet providers to give public-security and state-security agencies technical interfaces, decryption, and other technical assistance for terrorism investigations.
Accounts of police access to telecommunications systems date back decades.
Minghui, a U.S.-based website that documents the persecution of Falun Gong practitioners and publishes first-hand accounts from China, has documented cases in which practitioners were detained after authorities monitored their telephone or internet communications.
In a 2006 article, Minghui described special police-monitoring interfaces connecting Chinese telecommunications equipment with public-security systems. The account said police could use the systems to trace calls and identify people contacted by someone under surveillance.
The article concerned an earlier generation of telecommunications equipment, two decades before the newly reported Zbtlink backdoors.
US Takes Action
The findings were issued months after the Federal Communications Commission (FCC) moved to restrict approval of new foreign-made consumer routers over national security concerns.
On March 23, the FCC added foreign-produced consumer-grade routers to its Covered List following a national security determination by executive branch agencies. The action prevents approval of new covered router models unless an exemption applies; equipment already authorized can remain on the market.
The FCC said malicious actors had exploited weaknesses in foreign-made routers to attack U.S. households, enable espionage, and disrupt networks. It also said foreign-made routers were involved in the Volt Typhoon, Flax Typhoon, and Salt Typhoon cyber campaigns targeting U.S. infrastructure.
As of Aug. 28, VulnCheck’s advisories did not list patched software versions for Speakingstone or Darklantern, leaving owners of affected routers without a published fix.






















