DARKLANTERN is a firmware-resident backdoor tracked as CVE-2026-74233 that affects certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router products, including internationally distributed OEM and white-label devices. It exposes a WAN-facing UDP service through the default firewall and implements an unencrypted remote-management protocol with ineffective authentication. Its token scheme relies on a static embedded value, and its MAC-address validation accepts an all-zero wildcard value, permitting unauthenticated remote access. DARKLANTERN can disclose router and network-identifying information and execute attacker-supplied shell commands with root privileges. It was identified in 2019-era firmware and has been observed across multiple ZBT router models; not all ZBT-derived firmware is known to contain it. Internet measurement identified publicly reachable instances in multiple countries, but exposure alone does not establish device compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
DARKLANTERN operates as the infosrvd service on UDP port 9992, which the firmware firewall permits from the internet.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
DARKLANTERN ... Backdoor écoutant sur UDP/9992, ouvert par défaut dans le firewall du routeur ... exécute des commandes shell arbitraires.
„Die IT-Forscher haben eine Telnet-Sicherheitslücke im Router missbraucht, um dadurch root-Zugriff zu erlangen und die Firmware zu extrahieren.“
„Die Anfrage enthält ebenfalls das Gerätemodell, die Firmware-Version, MAC-Adresse, SSID des WLANs, LAN-IP, Uptime und mehr.“
SPEAKINGSTONE and DARKLANTERN allow a remote attacker to connect to the device without authentication and execute commands with root privileges. DARKLANTERN's token is derived from a hard-coded value and its MAC-address check can be bypassed with six null bytes.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote-command backdoor in ZBT router firmware. Although it nominally requires a token and the router MAC address, the token can be derived from a hard-coded firmware value and the MAC check can be bypassed by supplying six null bytes, enabling arbitrary remote command execution.
Implant de firmware pour routeurs ZBT fournissant un accès root distant non authentifié. Il expose un service UDP/9992, divulgue des informations sur le routeur et exécute des commandes shell arbitraires; son mécanisme de jeton MD5 à clé statique est forgeable et le contrôle MAC peut être contourné avec un champ MAC nul.
A remotely reachable router-firmware backdoor which exposes UDP port 9992, discloses device details in response to a fixed probe, and permits arbitrary root command execution. Its static checksum salt and MAC-address filtering can be trivially bypassed, including by using an all-zero MAC field.
A factory-installed router firmware implant exposed through an internet-reachable UDP/9992 service. Ineffective authentication permits unauthenticated remote attackers to execute commands as root; command responses use UDP/8897 according to the advisory text and scanner.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.