Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Aug 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
SPEAKINGSTONE is a firmware-resident backdoor implant tracked as CVE-2026-74232 and identified in routers manufactured by Shenzhen Zhibotong Electronics (ZBT), including internationally sold OEM and white-label products.
Profile source: Mallory opens in a new tabSPEAKINGSTONE
SPEAKINGSTONE is a firmware-resident backdoor implant tracked as CVE-2026-74232 and identified in routers manufactured by Shenzhen Zhibotong Electronics (ZBT), including internationally sold OEM and white-label products. It initiates outbound UDP command-and-control communications, allowing it to operate from devices behind NAT. The implant transmits device-fingerprinting and network data and accepts remotely issued commands. Supported functions include arbitrary root-level command execution, collection of WAN PPPoE usernames and passwords, modification of DNS-hijacking rules, reverse SSH tunnel management, and command-and-control reconfiguration. Its communications lack secure authentication, creating a risk that an attacker able to impersonate or intercept its controller can take control of an affected router. Sinkholing of a backup controller identified hundreds of beaconing devices, predominantly on Chinese carrier networks. ZBT characterized the functionality as an after-sales technical-support mechanism; no fixed firmware release was identified for affected devices.
C2 tracking
Derp observations, rolling seven-day window
Exploited software
MITRE ATT&CK
Reporting
VulnCheck identified DARKLANTERN and SPEAKINGSTONE, two previously undocumented firmware implants in cellular routers made by Shenzhen Zhibotong Electronics (ZBT)/MoreQuick and sold internationally under ZBTlink and numerous OEM brands. Tracked as CVE-2026-74232 and CVE-2026-74233, DARKLANTERN exposes an unauthenticated UDP service on port 9992 that permits arbitrary commands as root. SPEAKINGSTONE beacons over UDP port 10000, including from devices behind NAT, and supports remote command execution, PPPoE/WAN credential theft, DNS hijacking, reverse SSH tunneling, and C2 reconfiguration; affected firmware also includes the previously reported ENDLESSDOORS implant in some models. Internet scans found 203 DARKLANTERN-exposed devices in 22 countries across at least 16 device models. After registering an abandoned SPEAKINGSTONE backup C2 domain, researchers received beacons from 392 devices, 390 of them in China and largely appearing to be China Mobile customer-premises equipment; the implant’s primary C2 domain remained active. No separate criminal exploitation campaign has been confirmed, but organizations should regard affected routers as potentially compromised, restrict inbound UDP 9992 and outbound UDP 10000 traffic, investigate connected devices, and replace hardware where feasible. ZBTlink said it suspended sales of affected routers and took related software offline while developing updates, though no confirmed vendor fix was reported.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.