Skip to content

DARKLANTERN

DARKLANTERN is a firmware-resident backdoor tracked as CVE-2026-74233 that was identified in certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router firmware builds, including internationally distributed white-label and OEM products.

Profile source: Mallory opens in a new tab

DARKLANTERN

Family profile

DARKLANTERN is a firmware-resident backdoor tracked as CVE-2026-74233 that was identified in certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router firmware builds, including internationally distributed white-label and OEM products. It operates as a WAN-exposed UDP service and uses an unencrypted, effectively unauthenticated protocol to disclose router and network configuration data and accept arbitrary shell commands. Its nominal token and MAC-address validation can be bypassed, allowing a remote unauthenticated attacker to execute commands with root privileges on affected routers. The implant was identified in multiple ZBT router models, although its presence is not universal among ZBT-derived firmware. Internet measurement identified publicly reachable instances in multiple countries. DARKLANTERN has been reported alongside the related ZBT firmware implants SPEAKINGSTONE and ENDLESSDOORS. No fixed firmware release for DARKLANTERN was identified in the available reporting.

Capabilities

  • Initial Access
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Aug 28, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • SG1

Leading providers

  • DigitalOcean, LLC1

Infrastructure traits

  • Hosting 1

Exploited software

Vulnerabilities linked to DARKLANTERN

1 CVEs

MITRE ATT&CK

DARKLANTERN in ATT&CK

12 distinct techniques

Reporting

Research mentioning DARKLANTERN

Aug 28
Heise

(OEM-)China-Router von ZBT mit Backdoors | heise online

VulnCheck identified DARKLANTERN and SPEAKINGSTONE, two previously undocumented firmware implants in cellular routers made by Shenzhen Zhibotong Electronics (ZBT)/MoreQuick and sold internationally under ZBTlink and numerous OEM brands. Tracked as CVE-2026-74232 and CVE-2026-74233, DARKLANTERN exposes an unauthenticated UDP service on port 9992 that permits arbitrary commands as root. SPEAKINGSTONE beacons over UDP port 10000, including from devices behind NAT, and supports remote command execution, PPPoE/WAN credential theft, DNS hijacking, reverse SSH tunneling, and C2 reconfiguration; affected firmware also includes the previously reported ENDLESSDOORS implant in some models. Internet scans found 203 DARKLANTERN-exposed devices in 22 countries across at least 16 device models. After registering an abandoned SPEAKINGSTONE backup C2 domain, researchers received beacons from 392 devices, 390 of them in China and largely appearing to be China Mobile customer-premises equipment; the implant’s primary C2 domain remained active. No separate criminal exploitation campaign has been confirmed, but organizations should regard affected routers as potentially compromised, restrict inbound UDP 9992 and outbound UDP 10000 traffic, investigate connected devices, and replace hardware where feasible. ZBTlink said it suspended sales of affected routers and took related software offline while developing updates, though no confirmed vendor fix was reported.

Aug 28
Security Online Info

ZBT Router Backdoor Sinkholed by VulnCheck

Aug 27
Vulncheck

Chinese Implants in the Supply Chain | Blog | VulnCheck

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.