...
In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.
The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.
The researchers then found both programs operating on routers already connected to the internet.
...
Baines described Speakingstone in his Aug. 27 post as software that "phones home to ZBT infrastructure and supports remote surveillance." ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.
The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.
Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.
Jeremiah Ford, a senior cloud support engineer with 25 years of experience in information technology, said the most serious issue was that the routers exposed administrator-level access directly to the public internet.
...
The same Speakingstone software found on the China Mobile-linked routers was present in the Deep Orange router VulnCheck bought through Amazon in the United States.
The researchers traced the device to Zbtlink. That device also contained Darklantern.
Zbtlink manufactures equipment that other companies can sell under different names, meaning buyers may not see the Zbtlink name on the product.
VulnCheck traced Zbtlink hardware to brands and products sold in multiple countries, including the United States, but cautioned that not every product using Zbtlink hardware necessarily contains the backdoors.
...