Implants in the Supply Chain
Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...
Indicators of Compromise
- ip: 47.107.224.89
- hash: 7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245
- hash: ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926
- hash: b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818
- ip: 45.156.37.159
- hash: 4309d107af6a23f4a7f841b9148258e1a280b972
- hash: 681b57b6bf79ff0fdcfd19633586a6dcd3491651
- domain: www.ac-link.com
- domain: www.findmyipaddr.com
Implants in the Supply Chain
Description
Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.vulncheck.com/blog/zbt-darklantern-speakingstone"]
- Adversary
- null
- Pulse Id
- 6a90b7387fc31b76fc1f2e4c
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip47.107.224.89 | — | |
ip45.156.37.159 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245 | — | |
hashae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926 | — | |
hashb77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818 | — | |
hash4309d107af6a23f4a7f841b9148258e1a280b972 | — | |
hash681b57b6bf79ff0fdcfd19633586a6dcd3491651 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainwww.ac-link.com | — | |
domainwww.findmyipaddr.com | — |
Threat ID: 6a914fc1acd9273b49a91739
Added to database: 08/28/2026, 09:07:13 UTC
Last updated: 08/28/2026, 16:03:20 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.