ctipilot.ch

SPEAKINGSTONE

tool · tool:speakingstone single-source

Phone-home implant (process yunmgrd, UDP/10000) pre-installed on ZBT/Zbtlink router and CPE models, beaconing to ZBT's own Alibaba Cloud infrastructure with a full device fingerprint and accepting unauthenticated plaintext commands (shell execution, PPPoE credential exfiltration, DNS-hijack list read/write, reverse SSH tunnel control). VulnCheck sinkholed its abandoned backup domain and captured 392 beacons, 390 from China and 83% on China Mobile's network (VulnCheck, 2026-08-27).

Coverage timeline
1
first 2026-08-06 → last 2026-08-06
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
3
see Related entities below
ATT&CK techniques
4
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
ALLNET ALL-WR1200AC-WRT (ZBT WG2626 OEM, rebrand lineage match — implant presence unconfirmed)Digineo AC1200 Pro (ZBT WG3526 OEM, rebrand lineage match — implant presence unconfirmed)OneX RV WIFI Route (ZBT-WE826 rebrand lineage match — implant presence unconfirmed)WiFlyer WG3526 (ZBT WG3526 OEM)ZBT-WE826-T2 and rebrands (Deep Orange)Zbtlink CPE2801Zbtlink WE1026-5G-WDZbtlink WE1326Zbtlink WE2007Zbtlink WE2008-DSIMZbtlink WE2416Zbtlink WE3326Zbtlink WE5927Zbtlink WE5931Zbtlink WE5931ACZbtlink WE826-T3-DSIM

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · ATT&CK page ↗

Stealth TA0005

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · ATT&CK page ↗

Command and Control TA0011

T1571Non-Standard Port×1

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · ATT&CK page ↗

Story timeline

  1. 2026-08-06ENDLESSDOORS (CVE-2026-66747) — twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement
    trending-vulnerabilitiesThe implant is not an intrusion — it is a vendor component started by the vendor's own init script

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • vulncheck.com2 (67%)
  • heise.de1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SPEAKINGSTONE (1)

2026-08-06 · view entry permalink →

NOTABLECVE-2026-66747updatedNATOB2

VulnCheck published an analysis on 2026-08-05 of what it names ENDLESSDOORS, a remote-access implant pre-installed on twenty router and CPE models from Zbtlink (Shenzhen Zhibotong Electronics), including units sold under a rebranded name through mainstream e-commerce platforms (VulnCheck, 2026-08-05). The implant is a customised build of the open-source rctl remote-control tool. VulnCheck's framing is the point of the research: this is not a memory-corruption bug in a parser but a component in the vendor's product, started at boot by the vendor's own init script, shipped across twenty models (VulnCheck, 2026-08-05).

Operationally, the device registers itself outbound to hardcoded command-and-control hosts with a short unauthenticated message carrying a device-class label and the unit's MAC address, and from that point there is no handshake, no key exchange, no negotiation — whatever the server sends afterwards is handed to a shell and executed as uid 0, with a separate command spinning up an interactive reverse shell (VulnCheck, 2026-08-05). The implant hides in plain sight by taking the name of a kernel worker thread, which in a process listing sits alongside the genuine kernel threads it imitates (VulnCheck, 2026-08-05). Because control depends only on reaching the device's chosen server rather than on any credential, whoever controls that infrastructure — or anyone who takes it over — controls every unit that still calls home. VulnCheck's guidance is to segment or replace: for anything carrying real traffic it advises replacing the device, or at minimum moving it behind strict egress control and treating its LAN as untrusted, noting that disabling the init script with shell access still leaves you trusting the rest of an image that shipped the implant (VulnCheck, 2026-08-05). No vendor remedy exists to weigh against that: VulnCheck states it did not notify Zbtlink, because there is no patch to coordinate and an early warning would reach whoever operates the command infrastructure rather than the device owners (VulnCheck, 2026-08-05).

Triage: routers legitimately make outbound connections for firmware update checks, NTP and vendor telemetry, so outbound-from-CPE alone is normal. The discriminators are that this connection persists as a long-lived channel rather than completing a transaction and closing, that the traffic is command-carrying in both directions rather than a fetch, and that it targets a fixed vendor-independent host on a high port rather than a documented update endpoint on standard ports.

There is no handshake, no key exchange, no negotiation.

started at boot by the vendor's own init script

The router's default firewall explicitly allows inbound connections to this port from anywhere on the internet.

Between August 18, 2026 and August 21, 2026 we’ve identified 203 internet-facing DARKLANTERN instances across 22 countries.

390 of 392 devices are in China. 83% are on China Mobile's network.

VulnCheck 2026-08-05
Updaterun 2026-08-29T0409Z-intelentitiestechniquesaffected_productssourcesevidencesourcing_notebody

VulnCheck traced the ZBT/Zbtlink supply chain further and published two additional pre-installed implants on the same platform family (VulnCheck, 2026-08-27). DARKLANTERN runs as the service infosrvd on UDP/9992, a port the router's default firewall explicitly opens to the internet; an unauthenticated 19-byte probe returns the device's model, firmware, MAC address, SSID and public IP, and a command packet passes an operator-supplied string directly to system(), where a semicolon breaks out of the fixed command prefix into arbitrary root shell execution with no length limit or character filtering (VulnCheck, 2026-08-27). The only gating fields are a keyed checksum computed from a hardcoded static salt and a MAC-address check that is bypassed outright by sending an all-zero MAC. VulnCheck's internet scanner found 203 DARKLANTERN-responsive devices across 22 countries between 18 and 21 August 2026, self-reporting across 16 different router models (VulnCheck, 2026-08-27). SPEAKINGSTONE instead beacons outbound over UDP/10000 to ZBT's own Alibaba Cloud infrastructure with a full device fingerprint, and accepts plaintext, unauthenticated commands to run arbitrary shell commands, exfiltrate WAN PPPoE credentials, write or read a DNS-hijack list, or open and close a reverse SSH tunnel; VulnCheck registered its abandoned hardcoded backup domain and captured 392 beacons by 21 August — 390 from China, 83% on China Mobile's network, and 363 of them a single carrier-CPE model — which VulnCheck reads as a domestic Chinese surveillance deployment running on the same firmware lineage sold to Americans through Amazon (VulnCheck, 2026-08-27). Supply-chain tracing via FCC filings, trademark records and archived web pages extends the confirmed OEM-rebrand list — previously US, Canadian and Australian units — to Germany: Digineo's AC1200 Pro and ALLNET's ALL-WR1200AC-WRT — though VulnCheck is explicit that it has not confirmed every rebrand carries the same implants (VulnCheck, 2026-08-27). No CVE has been assigned to either new implant. The 2026-08-27 post does not restate VulnCheck's remediation guidance or vendor-notification posture for DARKLANTERN/SPEAKINGSTONE specifically; VulnCheck's original ENDLESSDOORS guidance — device replacement rather than a patch, and no notification to Zbtlink since there is no fix to coordinate — is the only remediation position on record for this supply chain (VulnCheck, 2026-08-05).

Detection concept for the new implants: an unsolicited, long-lived, bidirectional command-carrying UDP channel from consumer-class CPE to a fixed external host on a non-standard port (SPEAKINGSTONE's UDP/10000 beacon), or an unauthenticated response to a 19-byte probe on UDP/9992 (DARKLANTERN), is not traffic ordinary router firmware generates — egress/ingress telemetry at the site boundary surfaces this even for an unmanaged device. Triage: routers legitimately make outbound connections for firmware checks, NTP and vendor telemetry, so outbound-from-CPE alone is not a discriminator; the tell is the fixed vendor-independent destination and the bidirectional command-carrying pattern, or an inbound-accepted session on 9992/8897 from an internet-routable source.

vulnerability06 Aug 04:11Zsingle-sourceOpen finding ↗