← All stories
● Covered by 3 sources · 3 reportsMedium impact

Chinese APT UAT-7810 Develops New Malware to Expand ORB Network

🔄 Updated 85d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • APT UAT-7810 is expanding their ORB network.
  • New malware: LONGLEASH, DOGLEASH, JARLEASH identified.
  • Exploits vulnerabilities in Ruckus and ASUS AiCloud routers.
  • Network used for cyber espionage against high-value targets.
  • Multiple IPs and servers already identified for payload deployment.

New Malware from UAT-7810

Chinese advanced persistent threat (APT) group UAT-7810 has introduced several new malware strains to enhance their Operational Relay Box (ORB) network, which is used for cyber espionage. The malware, identified as LONGLEASH, DOGLEASH, and JARLEASH, is designed to exploit known vulnerabilities in small office/home office (SOHO) routers, particularly Ruckus and ASUS AiCloud routers.

Vulnerabilities Targeted

The newly developed malware targets previously identified vulnerabilities within these devices, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 for Ruckus routers, and CVE-2025-2492 for ASUS AiCloud routers. These exploits allow the group to gain unauthorized access to compromised devices, enhancing their ability to perform undetected cyber operations.

Threat Infrastructure

The ORB network, a sophisticated infrastructure managed by UAT-7810, is used as a relay point for other groups with aligned interests such as UAT-5918. This allows for the anonymous proxying of network traffic, providing plausible deniability and obscuring the actual origin of attacks, making tracing efforts challenging.

Implications for Cybersecurity

As identified by Cisco Talos researchers, these developments pose significant concerns for cybersecurity, particularly for critical infrastructure entities that might be targeted by such advanced attacks. The efficient use of such networks for espionage activities indicates an ongoing and persistent threat, necessitating robust detection and patch management strategies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Cisco's Talos researchers warn that the China-linked APT, tracked as UAT-7810, has introduced new backdoors including LongLeash, and two others named DogLeash and JarLeash. This expansion enhances its operational capabilities for espionage, primarily targeting vulnerable SOHO routers.

UAT-7810, a Chinese APT actor, has developed new LONGLEASH malware to enhance its ORB network, exploiting vulnerabilities in networking devices. This development is significant as it indicates an ongoing strategy to utilize these networks for high-profile attacks, possibly threatening critical infrastructure.

Chinese hacking group UAT-7810 has developed LONGLEASH malware to strengthen their Operational Relay Box (ORB) network. This evolution aims to compromise vulnerable internet-facing devices, particularly unpatched Ruckus routers, allowing for improved evasion of detection and attribution.