SPEAKINGSTONE
SPEAKINGSTONE is a firmware-resident remote-access implant in certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router products, tracked as CVE-2026-74232.
Profile source: Mallory opens in a new tabSPEAKINGSTONE
Family profile
SPEAKINGSTONE is a firmware-resident remote-access implant in certain Shenzhen Zhibotong Electronics (ZBT/Zbtlink) router products, tracked as CVE-2026-74232. It initiates periodic outbound UDP command-and-control communications, allowing it to operate from routers behind NAT. The implant transmits device fingerprinting information and accepts plaintext remote commands that permit arbitrary command execution with root privileges. Supported functions include collection of WAN PPPoE usernames and passwords, modification and retrieval of DNS-hijacking rules that can redirect LAN clients, reverse SSH tunnel management, and command-and-control reconfiguration. It was identified in 2019-era firmware on a white-label ZBT-WE826-T2 device and has also been associated with ZBT L3_V2_8 and other ZBT- and MoreQuick-derived products. ZBT hardware is distributed internationally through OEM and white-label channels, although implant presence is not universal across ZBT-derived firmware. Sinkholing of an unregistered backup command-and-control endpoint observed hundreds of beaconing devices, predominantly China Mobile-associated devices in China; these observations establish deployed implant-bearing devices but do not independently establish third-party compromise or a distinct criminal exploitation campaign.
Capabilities
- Credential Theft
- Exfiltration
- Post Exploitation
Exploited software
Vulnerabilities linked to SPEAKINGSTONE
1 CVEsMITRE ATT&CK
SPEAKINGSTONE in ATT&CK
23 distinct techniquesReporting
Research mentioning SPEAKINGSTONE
(OEM-)China-Router von ZBT mit Backdoors | heise online
VulnCheck identified DARKLANTERN and SPEAKINGSTONE, two previously undocumented firmware implants in cellular routers made by Shenzhen Zhibotong Electronics (ZBT)/MoreQuick and sold internationally under ZBTlink and numerous OEM brands. Tracked as CVE-2026-74232 and CVE-2026-74233, DARKLANTERN exposes an unauthenticated UDP service on port 9992 that permits arbitrary commands as root. SPEAKINGSTONE beacons over UDP port 10000, including from devices behind NAT, and supports remote command execution, PPPoE/WAN credential theft, DNS hijacking, reverse SSH tunneling, and C2 reconfiguration; affected firmware also includes the previously reported ENDLESSDOORS implant in some models. Internet scans found 203 DARKLANTERN-exposed devices in 22 countries across at least 16 device models. After registering an abandoned SPEAKINGSTONE backup C2 domain, researchers received beacons from 392 devices, 390 of them in China and largely appearing to be China Mobile customer-premises equipment; the implant’s primary C2 domain remained active. No separate criminal exploitation campaign has been confirmed, but organizations should regard affected routers as potentially compromised, restrict inbound UDP 9992 and outbound UDP 10000 traffic, investigate connected devices, and replace hardware where feasible. ZBTlink said it suspended sales of affected routers and took related software offline while developing updates, though no confirmed vendor fix was reported.