VulnCheck discloses two factory implants in ZBT router firmware: SPEAKINGSTONE and DARKLANTERN. Both provide unauthenticated root command execution. SPEAKINGSTONE beacons to C2 via UDP 10000; DARKLANTERN listens on UDP 9992. Affected models listed; IOCs published. Majority of SPEAKINGSTONE beacons from China Mobile network.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Domain |
www.findmyipaddr.com
|
Backup C2 domain registered by VulnCheck for sinkholing. | T1071.001 |
| Domain |
www.ac-link.com
|
Primary command-and-control domain for SPEAKINGSTONE implant. | T1071.001|T1573.001 |
| Filename |
infosrvd
|
DARKLANTERN service binary name. | T1543.002 |
| Filename |
inetdetect
|
Additional binary associated with implants. | T1543.002 |
| Filename |
yunmgrd
|
SPEAKINGSTONE service binary name. | T1543.002 |
| Filepath |
/tmp/info.txt
|
Temporary file used by implant. | T1005 |
| Filepath |
/etc/exec/cmd
|
Path used for command execution. | T1059.004 |
| Filepath |
/tmp/yunclient.conf
|
Configuration file for SPEAKINGSTONE client. | T1505.003 |
| Ipaddress |
47.107.224.89
|
Chinese C2 server for ENDLESSDOORS backdoor. | T1071|T1105 |
| Malwarename | SPEAKINGSTONE | Name assigned to the implant by VulnCheck. | None |
| Malwarename | DARKLANTERN | Name assigned to the implant by VulnCheck. | None |
| Malwarename | ENDLESSDOORS | Previously disclosed implant name. | None |
| Port | UDP/9992 | Inbound listener for DARKLANTERN service infosrvd. | T1571 |
| Port | UDP/10000 | Outbound beacon port for SPEAKINGSTONE service yunmgrd. | T1571 |
| Port | UDP/8897 | Port for DARKLANTERN responses (scanner uses 8897, Suricata rule mentions 8898). | T1571 |
| Sha256hash |
b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818
|
SHA-256 hash of yunmgrd binary (SPEAKINGSTONE). | T1543.002 |
| Sha256hash |
7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245
|
SHA-256 hash of infosrvd binary (DARKLANTERN). | T1543.002 |
| Sha256hash |
ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926
|
SHA-256 hash of inetdetect binary. | T1543.002 |
| Vulnerability | CVE-2026-74232 | SPEAKINGSTONE implant vulnerability. | None |
| Vulnerability | CVE-2026-74233 | DARKLANTERN implant vulnerability. | None |
| Vulnerability | CVE-2026-66747 | ENDLESSDOORS implant vulnerability (previously disclosed). | None |
| Code | Title |
|---|---|
| T1543.002 | Create or Modify System Process: Systemd Service - implants run as services yunmgrd and infosrvd. |
| T1059.004 | Command and Scripting Interpreter: Unix Shell - arbitrary command execution as root. |
| T1571 | Non-Standard Port - SPEAKINGSTONE uses UDP 10000, DARKLANTERN uses UDP 9992/8897. |
| T1095 | Non-Application Layer Protocol - custom UDP protocol for C2. |
| T1005 | Data from Local System - exfiltration of PPPoE username/password. |
| T1552.001 | Credentials from Password Stores - exfiltrate PPPoE credentials. |
| T1090.001 | Proxy Connection: Internal Proxy - reverse SSH tunnel. |
| T1190 | Exploit Public-Facing Application - DARKLANTERN command injection via UDP 9992. |
| T1210 | Exploitation of Remote Services - DARKLANTERN accessible from internet. |
| T1505.003 | Server Software Component: Web Shell - implant provides remote access via custom service. |
| Type | Value |
|---|---|
| Country | China |
| Other | ZBT router users globally |
| Region | China |
| Sector | Telecommunications |
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics ( ZBT ), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named
That unit predates
The company registered the domain and stood up a server running a reverse-engineered implementation of the protocol. Beacons began arriving as soon as the server was live. As of August 21, 392 unique devices had reported in, of which 390 were in
VulnCheck published the following indicators of compromise (IoCs) - Domains - www.ac-link[.]com , the
That statement addresses