Executive Summary
In August 2026, VulnCheck disclosed two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, found in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Both implants, tracked as CVE-2026-74232 and CVE-2026-74233 with CVSS scores of 9.3-9.8, provide unauthenticated remote attackers with root access to affected devices. SPEAKINGSTONE operates as a surveillance implant that beacons to hardcoded command-and-control servers, while DARKLANTERN listens on UDP port 9992 with ineffective authentication. VulnCheck identified over 200 internet-facing DARKLANTERN instances across 22 countries and received beacons from 392 unique devices when they registered the backup C2 domain. This incident highlights the growing threat of supply chain attacks targeting network infrastructure, particularly as organizations increasingly rely on low-cost networking equipment from overseas manufacturers. The discovery comes amid heightened awareness of nation-state activities targeting critical infrastructure and follows similar findings in Chinese-manufactured networking equipment.
Why This Matters Now
This incident exemplifies the escalating supply chain security crisis in networking infrastructure, where factory-embedded surveillance capabilities threaten organizational security at the foundational network level, requiring immediate assessment of hardware provenance and zero-trust network architectures.
Attack Path Analysis
Attackers compromised ZBT routers through supply chain insertion of factory implants SPEAKINGSTONE and DARKLANTERN, providing immediate root access. The implants established persistent command and control channels via hardcoded C2 servers and open UDP listeners. Lateral movement occurred through the compromised router's position as a network gateway, enabling interception and manipulation of all local network traffic. Data exfiltration capabilities included stealing WAN credentials, DNS hijacking, and establishing covert tunnels for ongoing surveillance operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Supply chain compromise through factory-installed implants SPEAKINGSTONE (yunmgrd service) and DARKLANTERN (infosrvd service) providing unauthenticated root access to ZBT routers
Related CVEs
CVE-2026-74232
CVSS 9.8SPEAKINGSTONE implant in ZBT router firmware provides unauthenticated remote command execution as root via hardcoded C2 communication over UDP port 10000.
Affected Products:
Zbtlink L3_V2_8 – 3.0.0.4.528
Zbtlink WE826-T2 – 19.1101
ZBT ZBT-7628 – 1.0.0.2.007
ZBT ZBT-ZBT7621 – 1.0.0.3.001
MoreQuick MQAC-7620 – 1.0.0.2.000
Exploit Status:
exploited in the wildCVE-2026-74233
CVSS 9.8DARKLANTERN implant in ZBT router firmware allows unauthenticated remote command injection via infosrvd service on UDP port 9992 with ineffective authentication bypass.
Affected Products:
Zbtlink WE1326 – 19.1101
Zbtlink WE357 – 19.1101
Zbtlink WE5926 – 19.1101
Zbtlink WE826-T2 – 19.1101
Zbtlink WE2426-C – 19.1112
ZBT WG108 – 19.1101
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Server Software Component: Web Shell
Application Layer Protocol: File Transfer Protocols
Valid Accounts
Obfuscated Files or Information
Exfiltration Over C2 Channel
Proxy
Protocol Tunneling
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Vulnerability Scans
Control ID: 11.2.2
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.08
DORA – Third-party risk monitoring
Control ID: Article 28
CISA ZTMM 2.0 – Device Identity and Integrity
Control ID: Device Security
NIS2 Directive – Supply chain security measures
Control ID: Article 21.2(f)
ISO 27001:2022 – Information security policy for supplier relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical supply chain vulnerability in ZBT routers enables root access, lateral movement, and encrypted traffic interception across telecom infrastructure networks.
Internet
Factory implants in internet routers create command-and-control channels, compromising egress security and enabling unauthorized access to service provider networks.
Information Technology/IT
Zero trust segmentation and east-west traffic security compromised through embedded backdoors, affecting multicloud visibility and Kubernetes security implementations.
Government Administration
Supply chain compromise threatens government networks through hardcoded backdoors, bypassing standard security controls and enabling persistent surveillance capabilities.
Sources
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Accesshttps://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.htmlVerified
- VulnCheck ZBT DARKLANTERN SPEAKINGSTONE Supply Chain Researchhttps://www.vulncheck.com/blog/zbt-darklantern-speakingstoneVerified
- Zbtlink MQWRT infosrvd Command Injection Advisoryhttps://www.vulncheck.com/advisories/zbtlink-mqwrt-infosrvd-command-injectionVerified
- Zbtlink MQWRT yunmgrd Cloud C2 Implant Advisoryhttps://www.vulncheck.com/advisories/zbtlink-mqwrt-yunmgrd-cloud-c2-implantVerified
- ZBT Router Firmware Download Announcementhttps://www.zbtlink.com/pages/zbt-router-firmware-download-announcementVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain this supply chain router compromise by limiting lateral movement through network segmentation and controlling outbound communications. The segmented architecture would reduce the blast radius from compromised gateway devices accessing connected network resources.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely reduce the scope of initial router compromise by constraining network access paths and limiting reachability to protected cloud workloads behind segmented boundaries
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the privilege escalation impact by limiting access scope to specific network segments and reducing the blast radius of compromised router credentials
Control: East-West Traffic Security
Mitigation: East-west traffic security would likely constrain lateral movement by enforcing inspection and access controls on inter-network communications, reducing attacker reachability to connected network segments
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely reduce command and control effectiveness by constraining unauthorized outbound communications and limiting attacker communication channels across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Egress security and policy enforcement would likely constrain data exfiltration by limiting outbound communication paths and reducing the scope of unauthorized data transfers through controlled egress points
The residual impact would likely be limited to isolated network segments with reduced surveillance scope, as segmentation boundaries would constrain the attacker's visibility into protected cloud workloads and applications
Impact at a Glance
Affected Business Functions
- Network Infrastructure
- Internet Connectivity
- Remote Access Services
- IoT Device Management
Estimated downtime: N/A
Estimated loss: N/A
WAN PPPoE credentials, DNS hijacking capabilities, complete network traffic interception, and full administrative access to router configurations affecting 203+ identified internet-facing devices across 22 countries with potential for surveillance and data exfiltration through hardcoded C2 infrastructure.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound connections to hardcoded C2 domains and detect abnormal beacon patterns
- • Deploy zero trust segmentation to isolate network devices and prevent lateral movement from compromised routers into internal networks
- • Enable multicloud visibility and control to detect anomalous router behavior, unauthorized services, and suspicious network traffic patterns
- • Establish threat detection and anomaly response capabilities to identify covert tools, unauthorized remote access, and baseline deviations in network device behavior
- • Apply cloud firewall controls with URL filtering and intrusion prevention to block known malicious domains and detect exploit patterns in router communications



