Chinese advanced persistent threat (APT) group UAT-7810 has introduced several new malware strains to enhance their Operational Relay Box (ORB) network, which is used for cyber espionage. The malware, identified as LONGLEASH, DOGLEASH, and JARLEASH, is designed to exploit known vulnerabilities in small office/home office (SOHO) routers, particularly Ruckus and ASUS AiCloud routers.
The newly developed malware targets previously identified vulnerabilities within these devices, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 for Ruckus routers, and CVE-2025-2492 for ASUS AiCloud routers. These exploits allow the group to gain unauthorized access to compromised devices, enhancing their ability to perform undetected cyber operations.
The ORB network, a sophisticated infrastructure managed by UAT-7810, is used as a relay point for other groups with aligned interests such as UAT-5918. This allows for the anonymous proxying of network traffic, providing plausible deniability and obscuring the actual origin of attacks, making tracing efforts challenging.
As identified by Cisco Talos researchers, these developments pose significant concerns for cybersecurity, particularly for critical infrastructure entities that might be targeted by such advanced attacks. The efficient use of such networks for espionage activities indicates an ongoing and persistent threat, necessitating robust detection and patch management strategies.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cisco's Talos researchers warn that the China-linked APT, tracked as UAT-7810, has introduced new backdoors including LongLeash, and two others named DogLeash and JarLeash. This expansion enhances its operational capabilities for espionage, primarily targeting vulnerable SOHO routers.
UAT-7810, a Chinese APT actor, has developed new LONGLEASH malware to enhance its ORB network, exploiting vulnerabilities in networking devices. This development is significant as it indicates an ongoing strategy to utilize these networks for high-profile attacks, possibly threatening critical infrastructure.
Chinese hacking group UAT-7810 has developed LONGLEASH malware to strengthen their Operational Relay Box (ORB) network. This evolution aims to compromise vulnerable internet-facing devices, particularly unpatched Ruckus routers, allowing for improved evasion of detection and attribution.