SPEAKINGSTONE is a firmware-resident remote-access implant in certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router products, tracked as CVE-2026-74232. It initiates periodic outbound UDP command-and-control communications, allowing it to operate from routers behind NAT. The implant transmits device fingerprinting information and accepts plaintext remote commands that permit arbitrary command execution with root privileges. Supported functions include collection of WAN PPPoE usernames and passwords, modification and retrieval of DNS-hijacking rules that can redirect LAN clients, reverse SSH tunnel management, and command-and-control reconfiguration. It was identified in 2019-era firmware on a white-label ZBT-WE826-T2 device and has also been associated with ZBT L3_V2_8 and other ZBT- and MoreQuick-derived products. ZBT hardware is distributed internationally through OEM and white-label channels, although implant presence is not universal across ZBT-derived firmware. Sinkholing of an unregistered backup command-and-control endpoint observed hundreds of beaconing devices, predominantly China Mobile-associated devices in China; these observations establish deployed implant-bearing devices but do not independently establish third-party compromise or a distinct criminal exploitation campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SPEAKINGSTONE operates as the yunmgrd service and causes the router to send data to a hard-coded C2 address over UDP port 10000.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
„Die IT-Forscher haben eine Telnet-Sicherheitslücke im Router missbraucht, um dadurch root-Zugriff zu erlangen und die Firmware zu extrahieren.“
SPEAKINGSTONE and DARKLANTERN allow a remote attacker to connect to the device without authentication and execute commands with root privileges. DARKLANTERN's token is derived from a hard-coded value and its MAC-address check can be bypassed with six null bytes.
SPEAKINGSTONE carries a hardcoded backup C2 domain that the implant reaches for where a primary server was never configured.
“SPEAKINGSTONE is the more capable ZBT router backdoor. It can run arbitrary commands, steal PPPoE ISP credentials, hijack DNS, and open reverse SSH tunnels.”
Its command protocol allows remote operators to... establish a reverse SSH tunnel.
SPEAKINGSTONE, operating as the yunmgrd service, has the router send data to a hard-coded command-and-control-server address over UDP port 10000.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A router-resident root backdoor that initiates outbound UDP C2 communications, allowing attackers to execute arbitrary commands, steal PPPoE credentials, alter DNS records, redirect LAN devices to attacker-controlled servers, and establish reverse SSH tunnels. Its device-initiated C2 design permits operation behind NAT.
Implant de firmware ZBT de type RAT qui transmet une empreinte détaillée du périphérique à un C2 et permet l'exécution de commandes, l'exfiltration d'identifiants PPPoE, le détournement DNS, un tunnel SSH inverse et la modification des C2 de secours.
An outbound-beaconing router-firmware backdoor using the custom zbtProtocol, allowing operation even behind NAT or firewalls. It fingerprints devices to C2 infrastructure and supports arbitrary command execution, theft of WAN PPPoE credentials, DNS-hijack-list modification, and reverse SSH tunneling.
A factory-installed router firmware implant that phones home to a hardcoded C2 server and enables root-level remote command execution, PPPoE credential theft, DNS-hijack-list manipulation, and reverse SSH tunneling. Its outbound beaconing allows operation from behind NAT and ordinary egress filtering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.