This week, security researchers raised concerns after discovering a hidden remote access service pre-installed on the Unitree Go1 robot dog, warning that the backdoor is activated as soon as the device detects an internet.
See also: Chinese hackers Earth Alux use VARGEIT & COBEACON backdoors
According to documents published by researchers Andreas Makris and Kevin Finisterre, the four-legged robot developed by Chinese company Unitree Robotics contains the unpublished tunnel service, which automatically pings unitree.com to initiate its connection if a specific variable is triggered.

Researchers report that the backdoor in the Unitree Go1 uses CloudSail , a remote access solution developed by Chinese company Zhexi Technology . Although CloudSail is normally intended for legitimate remote device management, it is used to provide external access to the robotic dog.
The device, which sells in the United States for less than $4,000, also contains remnants of an older, inactive code base for an alternative tunnel client, indicating the existence of development leftovers.
See also: Russian hackers develop SilentPrism and DarkWisp backdoors
The researchers report that data from CloudSail's API revealed that a total of 1,919 devices have connected to this service at some point, although only two remain active at this time.

According to a report, the robotic dogs also ship with default SSH credentials. If these are not changed, attackers could gain access to the underlying Raspberry Pi, thus opening a path for lateral traffic within local networks.
The discovery of this backdoor, which has been deployed without users' knowledge or consent, constitutes a significant security risk, the researchers warned, highlighting the possibility of remote exploitation in sensitive environments where the Unitree Go1 robot dogs may be used.
The report also raises concerns that similar hidden accesses could exist in other Unitree products, including newer models like the Go2 or the company's humanoid robots.
See also: FamousSparrow hackers distribute SparrowDoor & ShadowPad backdoors
Researchers said the discovery raises many questions about the company's intentions.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
