VulnCheck identified DARKLANTERN and SPEAKINGSTONE, two previously undocumented firmware implants in cellular routers made by Shenzhen Zhibotong Electronics (ZBT)/MoreQuick and sold internationally under ZBTlink and numerous OEM brands. Tracked as CVE-2026-74232 and CVE-2026-74233, DARKLANTERN exposes an unauthenticated UDP service on port 9992 that permits arbitrary commands as root. SPEAKINGSTONE beacons over UDP port 10000, including from devices behind NAT, and supports remote command execution, PPPoE/WAN credential theft, DNS hijacking, reverse SSH tunneling, and C2 reconfiguration; affected firmware also includes the previously reported ENDLESSDOORS implant in some models.
Internet scans found 203 DARKLANTERN-exposed devices in 22 countries across at least 16 device models. After registering an abandoned SPEAKINGSTONE backup C2 domain, researchers received beacons from 392 devices, 390 of them in China and largely appearing to be China Mobile customer-premises equipment; the implant’s primary C2 domain remained active. No separate criminal exploitation campaign has been confirmed, but organizations should regard affected routers as potentially compromised, restrict inbound UDP 9992 and outbound UDP 10000 traffic, investigate connected devices, and replace hardware where feasible. ZBTlink said it suspended sales of affected routers and took related software offline while developing updates, though no confirmed vendor fix was reported.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
VulnCheck reported that SPEAKINGSTONE's primary C2 domain, www.ac-link[.]com, resolved to 47.107.224[.]89 when checked. It also published SHA-256 hashes and Suricata and YARA detection rules for associated components.
After registering the expired SPEAKINGSTONE backup C2 domain findmyipaddr[.]com, VulnCheck began receiving device beacons on August 21, 2026. The sinkhole recorded 392 unique devices, including 390 in China; 363 reported the L3_V2_8 model and firmware 3.0.0.4.528.
From August 18 through 21, 2026, VulnCheck identified 203 publicly reachable DARKLANTERN instances in 22 countries. The systems reported at least 16 device models; 103 were in the United States.
The analyzed ZBT-WE826-T2 firmware, which contained the SPEAKINGSTONE and DARKLANTERN implants but not ENDLESSDOORS, was built in 2019.
ZBTlink announced it would suspend sales of affected routers and take related software offline while developing updates. A vendor fix for affected devices had not been confirmed at the time of reporting.
VulnCheck assigned ENDLESSDOORS the identifier CVE-2026-66747 and rated it CVSS 9.3. The implant was reported to allow unauthenticated root-command execution through its insecure command-and-control mechanism.
VulnCheck identified ENDLESSDOORS in additional post-2019 ZBT firmware. The implant disguises its root-privileged process as kworker and uses a component called rctl, or Remote Control Linux, for separate C2 communications.
The SPEAKINGSTONE MQWrt yunmgrd implant was tracked as CVE-2026-74232 and DARKLANTERN infosrvd command injection as CVE-2026-74233. Both were rated CVSS v3 9.8, Critical.
VulnCheck identified the DARKLANTERN and SPEAKINGSTONE firmware implants in a Deep Orange-branded, white-labeled ZBT-WE826-T2 router. DARKLANTERN exposes unauthenticated root command execution via UDP/9992, while SPEAKINGSTONE provides outbound C2, command execution, credential theft, DNS hijacking, and reverse SSH functions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcetomshardware.com
Open sourcethehackernews.com
Open sourceheise.de
Open sourcesecurityonline.info
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.