
ZBT Routers Shipped with Triple Backdoor Suite Beaconing to PRC C2 Every 35 Seconds
ZBT routers left three high-severity backdoors in firmware that beacon to Chinese C2. The implants connect to the same Nanjing firm tied to FBI-disrupted proxy networks. Original reporting missed supply-chain and procurement links that turn these devices into persistent espionage platforms.
The backdoors predate public disclosure and were present in factory firmware. ENDLESSDOORS initiates outbound connections as frequently as every 35 seconds while the newer pair adds persistent reverse tunnels and log suppression. Analysis showed hardcoded C2 domains tied to Nanjing Xinjiuwei Network Technology, the same entity linked to the QTYF proxy frameworks disrupted by the FBI.
Procurement records and prior CVE patterns indicate this is not isolated. Similar embedded implants have appeared in other Chinese networking hardware used in critical infrastructure, where default trust in shipped devices bypasses normal detection. The original coverage listed the CVEs but omitted cross-referencing with contract awards showing ZBT routers in U.S. municipal and energy deployments.
Operational effect is straightforward: attackers gain network-level proxy access without user interaction, enabling the same reconnaissance and routing sold by QTYF. Independent verification of the beacon intervals and domains remains limited to the firmware samples examined.
Next steps include mandatory firmware audits on imported routers and potential sanctions on the Nanjing entity. Watch for additional models from the same supplier appearing in incident reports within the next quarter.
CISA: At least two additional Chinese router vendors will show comparable factory backdoors in public firmware scans within 60 days.
Sources (3)
- [1]The Hacker News Weekly Recap(https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html)
- [2]FBI QTYF Infrastructure Disruption(https://www.fbi.gov/news/press-releases/2026/08/fbi-disrupts-chinese-proxy-network)
- [3]WatchTowr ZBT Firmware Analysis(https://www.watchtowr.com/research/zbt-backdoors-2026)