VulnCheck ha individuato un implant nascosto nei firmware dei router Zbtlink, rivenduti anche con i marchi Wiflyer e altre etichette bianche su Amazon: il dispositivo contatta server in Cina ogni 35 secondi e accetta comandi shell con privilegi root

At least 20 Zbtlink router models ship with ENDLESSDOORS, a root backdoor that attempts C2 contact as often as every 35 seconds and accepts commands.

The hidden backdoor could allow attackers to gain unauthorized access to affected routers and other connected devices, cybersecurity company VulnCheck said.