Two implant families found on ZBT routers turn an abstract supply-chain concern into a practical home-network check. Researchers describe DARKLANTERN, which provides hidden root access, and SPEAKINGSTONE, which communicates with command infrastructure. The finding does not mean every router is infected. It means model, firmware and internet exposure should be verified before trust is assumed.
Quick Answer
Security researchers reported hidden access and remote-command implants on specific ZBT router firmware, including the ZBT-WE826-T2 in the newer case. South African users can begin with an R0 check: record the exact model and hardware revision, note the firmware version, disable unnecessary remote administration and confirm whether the device is exposed to the internet.
🔐 What the researchers found
VulnCheck's original report connects the new discovery with earlier work on affected ZBT devices. DARKLANTERN is described as a hardcoded root-account implant. SPEAKINGSTONE adds command-and-control behaviour that can provide remote shell-style access. The researchers observed internet-facing DARKLANTERN systems across multiple countries during an August scan window.
The newer supply-chain case involved a Deep Orange unit identified as a white-labelled ZBT-WE826-T2. That detail matters because branding on the outside may not reveal the original hardware or firmware lineage. It is also why broad claims about all devices from one country or every ZBT model would be irresponsible.
Neither source establishes that Evetech's current router range contains an affected unit. The response should be evidence-led: identify the device in use, then compare it with the model and firmware information in the research.
🧭 Run the R0 identification and exposure check
Photograph or record the model label, hardware revision and firmware build. Sign into the router from the local network and inspect remote-management settings, administrative accounts and update status. Do not expose the management page to the public internet merely to test it.

If an internet service provider manages the router, ask it to confirm the exact firmware and support status. Avoid applying an image intended for a different hardware revision. A mismatched firmware file can disable the device and may not remove a persistent implant.
The wireless router range and fibre router options provide replacement categories if trusted firmware is unavailable or the unit no longer receives security updates.
🛠️ Respond without destroying useful evidence
If the exact model and firmware match an affected case, disconnect unnecessary internet exposure and preserve the identifiers. Obtain firmware from a trusted vendor or service-provider channel. Where that cannot be done confidently, replacement is safer than repeatedly resetting unsupported equipment.
After installing trusted firmware or replacing the router, change the router administrator password and WiFi credentials. Review port forwards, DNS settings and connected clients. Update devices that may have shared credentials with the old router. A factory reset alone is not a complete response when the questionable code is part of the firmware image.
🌍 Keep the scope precise
The report is serious because hidden access can survive normal user behaviour and because white-labelling can obscure the original device. It is not evidence that every ZBT product, every imported router or every South African home network is compromised.
Use the published indicators and model information, involve the provider where appropriate and prefer supported hardware with a clear update path. The most useful action today is accurate identification, not panic.
Frequently Asked Questions
Which routers were named in the research?
The research focuses on ZBT devices and identifies the ZBT-WE826-T2 in the newer supply-chain case.
What did DARKLANTERN provide?
Researchers describe a hardcoded root account that could grant hidden administrative access.
What did SPEAKINGSTONE do?
It contacted command infrastructure and enabled remote shell-style control according to the researchers.
Does this mean every ZBT router is infected?
No. The findings are model and firmware specific, so identify the exact hardware and image before concluding exposure.
What is the first R0 response step?
Record the model, hardware revision and firmware version, then check remote administration and unexpected exposure.
Need a router with a clearer support path? Compare current options after recording the existing model, firmware and network requirements.