A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.

Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.

On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT’s most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.

Related:Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Backdoors in Chinese Tech

Chinese backdoors in network technologies has always been something of a stereotype, but perhaps never been this blatant.

Earlier this summer, Baines found a decade-old open source Linux remote control tool built into the router in his home office. “EndlessDoors,” as it’s called, was disguised as a kernel thread for ordinary system processing.

When a router such as his was powered on, it would beacon out to a strange domain, passing through any number of firewalls — because the connection initiates out to the Internet, rather than in from it — to establish command-and-control (C2) communications. Whomever controlled that domain could have commanded the router with root-level privileges. They could have spied on Baines’ Internet activity, stolen his credentials, or used it as an entry point into the rest of his network. EndlessDoors impacted dozens of router models.

Baines’s personal router was sold by Zbtlink, a ZBT brand. After discovering EndlessDoors, Baines went on Amazon and bought a different router from a different company, DeepOrange. The New York-based DeepOrange, like so many others, merely sells ZBT technology under its own brand name.

Interestingly, its router didn’t have EndlessDoors inside, but it did contain two other backdoors, which he named “SpeakingStone” and “DarkLantern.” Upon further inspection, these appeared to be earlier versions of EndlessDoors, implemented in ZBT firmware around 2019.

Countless Infected ZBT Routers

Unlike the other two implants, DarkLantern is a listener. ZBT, or an attacker in possession of its C2 infrastructure, can initiate a connection into a DarkLantern-infected router. ZBT boxes are explicitly designed to allow traffic to the UDP port the malware listens for, making the task simple unless the device is otherwise protected by third-party firewalls.

Related:N-able Bug Exposes Password Vault Master Keys

In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online. According to Baines, 103 of those connections originated from the US, with most of the rest coming from Russia, Taiwan, China, Ukraine, and Israel.

SpeakingStone is the more useful of the two since, like EndlessDoors, it initiates a connection out to its controlling domain. It first sends a variety of system data, including its GPS coordinates. It then accepts arbitrary system-level commands, plus specific malicious ones, such as the ability to perform Domain Name System (DNS) hijacking.

Luckily, whoever designed SpeakingStone hadn’t registered one of its C2 domains as of the time of the research, allowing Baines to grab and sinkhole it. He picked up 392 SpeakingStone connections to date, almost exclusively originating in China.

DarkLantern and SpeakingStone infections likely number only in the hundreds, because those versions of the implant are outdated and associated with end-of-life hosts. By contrast, EndlessDoors affects all of ZBT’s current firmware images.

Related:‘CoSnitch’ Attack Tricked Copilot Into Mapping Out Architecture

In trying to gauge the full blast radius of EndlessDoors, Baines laments, “the white-labeling and difficulty tracing things makes it really hard to say.” He guesses that the number of infected devices numbers in the six figures.

Defending Against Edge Device Implants

Dark Reading contacted ZBT and DeepOrange for this story, but neither company had responded at press time.

When Baines contacted the manufacturer, he recalls, “ZBT responded by shutting down all sales on Amazon and their website, and saying, ‘We’re going to fix this.’ And they’ve released some firmware that removes the implant, and subsequently have allowed you to purchase their stuff off Amazon again. So last week I purchased one of their devices under the WiFlyer brand name, and it came totally unpatched with the implant on it.”

Since backdoored ZBT routers remain available today on marketplaces like Amazon and Alibaba, and they’re sold under innocuous brand names, organizations need to proactively identify whether they’ve accidentally deployed Chinese spy tech.

“There are two hardware MAC addresses that are specifically allocated to ZBT, so look those up and try to track those down,” Baines advises. Besides that, he says, “the only thing I would do is unplug them and replace them.”

For some organizations, ripping and replacing routers won’t be an easy task. One of the primary features ZBT specializes in is building 4G and 5G connectivity into its products, Baines notes, “which means they’re deployed in places that are more remote and not necessarily easy to get to. An example is an oil pipeline: you want monitoring software on your pipeline, you need to get Internet connectivity so that telemetry can get shipped back. This is a good option because it will just connect to a cell service. But getting a human out there to both identify this is a ZBT system, and then replacing it, is non-trivial.”

At the end of the day, Baines says, “You have to really know the brand names that you’re interacting with very well. I hate to shell for [any specific company], but maybe just stick with the Ciscos and Ubiquitis of the world. They’re tried. True. We trust them.”





Source link

#

Comments are closed