网络安全组织发现美国在售路由器中存在监控后门
Cyber Group Finds Surveillance Backdoors In Routers Sold In US

原始链接: https://www.zerohedge.com/political/cyber-group-finds-surveillance-backdoors-routers-sold-us

网络安全公司 VulnCheck 在中国公司中兴智联(Zbtlink)生产的路由器中发现了危险的后门,其中包括在美国亚马逊上销售的产品。研究人员在固件中发现了名为“Speakingstone”和“Darklantern”的恶意程序,它们允许在没有密码的情况下进行未经授权的远程访问、窃取凭据以及重定向流量。 研究人员证实,这些后门至少从2019年起就已经存在。Speakingstone 似乎旨在协助国家背景的监控活动,证据是有数百台主要与中国移动相关的路由器正与中兴智联的基础设施进行通信。与此同时,Darklantern 对全球构成直接安全威胁,仅在美国境内就已发现超过100台受影响设备。 由于中兴智联生产的硬件会被多家公司贴牌销售,这些漏洞的影响范围难以追踪。此次发现凸显了人们对中国法律长期存在的担忧,该法律强制要求科技公司协助国家安全和情报机构。截至8月下旬,尚无修复这些后门的补丁。这一发现与美国联邦通信委员会(FCC)近期限制外国制造路由器的努力相一致,这些设备越来越多地与网络间谍活动及破坏基础设施的行为相关联。

相关文章

原文

Authored by Arthur Zhang via The Epoch Times,

Cybersecurity researchers have found surveillance backdoors in Chinese carrier routers made by Zbtlink and the same software in a different Zbtlink-made router sold through Amazon.

Ethernet cables are connected to the back of a wireless router. Mandel Ngan/AFP/Getty Images

Chinese law requires telecom and internet companies to provide technical assistance to police and state-security agencies.

In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.

The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.

The researchers then found both programs operating on routers already connected to the internet.

The findings expand VulnCheck's Aug. 5 investigation, which involved a different Zbtlink backdoor, named ENDLESSDOORS, found across more than 20 router models sold worldwide.

The newly discovered backdoors are older. VulnCheck found them in router software dating to 2019, years before ENDLESSDOORS was disclosed.

Speakingstone was not simply dormant code sitting inside old router software. It was still running.

VulnCheck researcher Jacob Baines registered an abandoned internet address that Speakingstone had been programmed to contact. Routers began sending information to it almost immediately, according to VulnCheck.

By Aug. 21, 392 routers had contacted the researchers. Of those, 390 were in China, and 83 percent were connected through China Mobile. Another 304 used Wi-Fi names beginning with "CMCC," China Mobile's commonly used abbreviation. Baines also detailed the figures in an Aug. 27 post on X.

Most - 363 of the 392 routers - were the same model running the same software version.

Baines said the pattern appeared to be a large deployment of routers provided by a telecommunications carrier to customers inside China. VulnCheck described it as "domestic Chinese surveillance technology."

The 392 routers may represent only part of the deployment. VulnCheck counted devices trying to reach the abandoned backup address; routers already communicating with the main server would not have appeared in that count, Baines explained.

Backdoor Could Redirect Traffic, Steal Credentials

Speakingstone gave whoever controlled its remote server broad access to an affected router.

VulnCheck said an operator could collect information about the device, obtain the credentials it used to connect to the internet, redirect internet traffic, and take control of the router. Its security advisory also says the software can open another path for remote access.

Baines described Speakingstone in his Aug. 27 post as software that "phones home to ZBT infrastructure and supports remote surveillance." ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.

The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.

Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.

Jeremiah Ford, a senior cloud support engineer with 25 years of experience in information technology, said the most serious issue was that the routers exposed administrator-level access directly to the public internet.

"This is the biggest problem," Ford said.

He said full control of a router could also give an attacker access to other devices on the same network.

Ford called the scale of the exposure significant, pointing to VulnCheck's finding that every detected Darklantern device offered administrator-level access without authentication.

"This is huge," he said. "And based on the numbers of devices affected by this, the scale could have been huge, if it went undetected."

The U.S. exposure extended beyond the single router the researchers bought on Amazon.

VulnCheck found 203 routers running Darklantern that were directly reachable from the internet across 22 countries. More than half - 103 - were in the United States. The devices identified themselves as 16 different ZBT router models.

Zbtlink Sold Under Other Brands

The same Speakingstone software found on the China Mobile-linked routers was present in the Deep Orange router VulnCheck bought through Amazon in the United States.

The researchers traced the device to Zbtlink. That device also contained Darklantern.

Zbtlink manufactures equipment that other companies can sell under different names, meaning buyers may not see the Zbtlink name on the product.

VulnCheck traced Zbtlink hardware to brands and products sold in multiple countries, including the United States, but cautioned that not every product using Zbtlink hardware necessarily contains the backdoors.

The discovery comes in a country where telecom and internet companies are legally required to assist police and state-security agencies.

China's Cybersecurity Law requires network operators to provide technical support and assistance for national-security work and criminal investigations.

Article 18 of China's Counter-Terrorism Law requires telecommunications and internet providers to give public-security and state-security agencies technical interfaces, decryption, and other technical assistance for terrorism investigations.

Accounts of police access to telecommunications systems date back decades.

Minghui, a U.S.-based website that documents the persecution of Falun Gong practitioners and publishes first-hand accounts from China, has documented cases in which practitioners were detained after authorities monitored their telephone or internet communications.

In a 2006 article, Minghui described special police-monitoring interfaces connecting Chinese telecommunications equipment with public-security systems. The account said police could use the systems to trace calls and identify people contacted by someone under surveillance.

The article concerned an earlier generation of telecommunications equipment, two decades before the newly reported Zbtlink backdoors.

US Takes Action

The findings were issued months after the Federal Communications Commission (FCC) moved to restrict approval of new foreign-made consumer routers over national security concerns.

On March 23, the FCC added foreign-produced consumer-grade routers to its Covered List following a national security determination by executive branch agencies. The action prevents approval of new covered router models unless an exemption applies; equipment already authorized can remain on the market.

The FCC said malicious actors had exploited weaknesses in foreign-made routers to attack U.S. households, enable espionage, and disrupt networks. It also said foreign-made routers were involved in the Volt Typhoon, Flax Typhoon, and Salt Typhoon cyber campaigns targeting U.S. infrastructure.

As of Aug. 28, VulnCheck's advisories did not list patched software versions for Speakingstone or Darklantern, leaving owners of affected routers without a published fix.

联系我们 contact @ memedata.com