Researchers at VulnCheck documented two implants named DarkLantern and SpeakingStone in the supply chain around Chinese-made ZBT networking gear. This is not a random virus you picked up after you plugged the box in. It is access sitting in equipment that small shops, remote sites, and regular people actually buy.
That difference is the whole story. One is a mistake you can patch. The other is a product that arrived with a spare key still on the ring.
What ZBT routers actually are
ZBT is a Chinese manufacturer of 4G and 5G routers and CPE boxes. You have seen these even if you never heard the name. They show up as cheap LTE failover routers, RV internet kits, white-label units sold under other brands, and the backup WAN a small business puts in a closet and forgets about.
Nobody treats those boxes like critical infrastructure. They get a SIM card, a default password that never changes, and a public address that faces the internet. Then they sit there for years. That is a system that works great for whoever wanted a quiet foothold.
DarkLantern and SpeakingStone are not drive-by junk
VulnCheck frames DarkLantern and SpeakingStone as implants in that supply chain, not as a commodity botnet spraying the whole internet. Implants mean persistence. They mean remote control. They mean someone wanted a foothold in the device itself, not just a lucky guess at a weak password.
If your router gets scanned because you left admin open, that is on you. If the gear arrives or updates with a hidden channel already in it, you never had a fair fight. You paid for a product. Someone else kept a way in.
Why cheap CPE is the easy target
Big companies have security teams. They ban vendors, inspect firmware, and watch their networks. You and I do not. The dentist office, the farm stand with a card reader, the shop running out of a garage, the cabin with a 4G router because fiber never showed up. Those are the networks that eat this gear.
Chinese operators have spent years living inside routers, firewalls, and VPN appliances. Pre-positioning on American networks is not a theory anymore. Cheap CPE from a Chinese OEM is a gift if your job is to sit quietly on someone else’s wire.
I have been doing this work for 30 years. Supply chain is the attack regular people cannot patch their way out of. You can change a password. You cannot easily prove the firmware you flashed is clean when the vendor and the update path sit in the same ecosystem that produced the implant.
What this means if you own one of these boxes
- If you have a ZBT router, or a white-label 4G or 5G box that looks like one, treat it as untrusted until you know otherwise.
- Do not use it as the front door to anything that matters. Payments, cameras, work VPN, medical gear, shop controls. Segment it or replace it.
- Remote administration should be off. Default passwords should already be gone. If they are not, you have a second problem on top of this one.
- Watch outbound connections. Implants have to call home. A cheap router talking to strange addresses is not just the cloud.
- A vendor firmware update is not automatically a fix when the supply chain is the issue. You need a vendor you can actually hold accountable.
We argued about chips. The firmware was always easier
We spent years arguing about whether China could hide a physical chip on a motherboard. That Super Micro scare got loud, then messy. Firmware implants are quieter and a lot more common. They do not need a microscopic extra part. They need a build pipeline, a signed update, or a factory image that nobody with a lab is going to reverse before it ships to a marketplace.
Every part of this is a system that does not work for normal people. The buying system rewards the cheapest box with the most antennas. The update system trusts the vendor. The network design assumes the router is the security device, not the threat. And we still pretend we can buy critical connectivity from a strategic competitor and act shocked when extra features show up.
I am not telling you to panic and throw every gadget in the lake. I am telling you to stop treating a ninety dollar LTE router from a Chinese OEM like it is a lock on your door. It might be a door they kept a copy of.
What I would do with this gear this week
- Inventory the routers, 4G failover boxes, and travel LTE units on your network. Find the actual manufacturer, not just the sticker brand.
- Pull ZBT and similar cheap CPE off anything tied to work, money, or safety. Replace it with gear from a vendor you can hold to account.
- Put remaining IoT and guest internet on its own VLAN or a separate switch so a compromised WAN box cannot wander your whole LAN.
- Turn off UPnP, WAN-side admin, and remote management. If you need access from outside, use a VPN you control.
- Log DNS and outbound connections from those devices if you can. You do not need a security operations center. You need to notice a box calling home at 3 a.m.
Freedom and control over your own data start with knowing what is sitting on your wire. This is not exotic nation-state theater. It is a reminder that the cheapest path into a network is often the device you paid for and plugged in yourself.
Primary Source: https://www.vulncheck.com/blog/zbt-darklantern-speakingstone
