They Sold You a Router With a Factory Surveillance Implant. There Is No Patch.
VulnCheck bought an $88 "Deep Orange" router on Amazon from a New York seller. White-label ZBT hardware out of Shenzhen. Firmware from 2019. Two factory implants sitting in it. Not a later hack. Built in.
Speakingstone phones home to ZBT's own infrastructure, steals ISP credentials, hijacks DNS, and can open a reverse SSH tunnel. Darklantern listens on the open internet and hands out root with no password. The same Speakingstone code is running on China Mobile customer routers inside China. VulnCheck called it "domestic Chinese surveillance technology." Then they found 103 Darklantern boxes reachable from the public internet in the United States.
There is no patched firmware. ZBT's last story, for an earlier implant, was "after-sales support." Support tools do not steal your PPPoE password or redirect your DNS.
If the box between your house and the rest of the world can be owned by anyone who finds it, you do not have a private network. You have a listening post you paid for.
Loading comments...