← Back to Feed

UAT-7810 continues building ORB networks using new malware

July 7, 2026 · Talos Intelligence · Severity: HIGH

Cisco Talos has identified ongoing activity by the China-linked APT group UAT-7810, which is expanding its Operational Relay Box (ORB) networks using newly developed malware. The group has upgraded its custom backdoor SHORTLEASH to a more advanced version called LONGLEASH and introduced two additional malware families: DOGLEASH (a C-based backdoor) and JARLEASH (a Java-based backdoor). UAT-7810 primarily exploits known vulnerabilities in unpatched Ruckus wireless routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and has recently targeted ASUS AiCloud Routers using CVE-2025-2492. The group operates through at least four newly identified servers (194.233.92[.]26, 217.15.160[.]247, 217.15.164[.]147, 95.182.100[.]231) to distribute malware across MIPS, ARM, and x64 platforms. LONGLEASH, built on the Boost.Asio library, enhances network performance and includes additional capabilities compared to its predecessor. UAT-7810’s infrastructure overlaps with other China-linked APTs like UAT-5918, though they remain distinct actors. These developments highlight the group’s persistent efforts to expand its attack infrastructure, posing a continued threat to high-value targets.

  • Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025.
  • UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets.
  • Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware, dubbed “SHORTLEASH,” with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as “LONGLEASH.”
  • Furthermore, we’ve discovered two new malware families in UAT-7810's arsenal: a C-based backdoor we track as “DOGLEASH” and a JAVA-based backdoor we track as “JARLEASH.”

UAT-7810 continues building ORB networks using new malware

Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918. Open-source reporting has also illustrated overlapping tooling between UAT-5918 and UAT-7810. However, at this time, Talos considers UAT-5918 and UAT-7810 separate APT actors tasked with their own set of objectives and targets.

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware dubbed “SHORTLEASH” with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as “LONGLEASH.”

Talos has also discovered two more previously unknown tools in UAT-7810's arsenal:

  • DOGLEASH: A malicious backdoor that can execute arbitrary shellcode on the compromised Linux device
  • LEASHTEST: A Linux binary (ELF) that is used for testing rudimentary functionality on MIPS-based embedded devices

Talos’ findings also illustrate that UAT-7810 used at least four new servers to host a variety of minor variations of DOGLEASH to deploy against compromised targets. An additional JAVA-based (JAR package) backdoor that we track as “JARLEASH” was also deployed by UAT-7810 on at least one of the three servers for administration purposes, including file management, FTP, SFTP, and Netcat.

UAT-7810 exploits n-day vulnerabilities

Talos has observed UAT-7810 primarily exploit known vulnerabilities in unpatched Ruckus wireless routers, a tactic UAT-7810 has used since 2025. CVEs exploited include:

UAT-7810 infrastructure

Talos discovered four new servers being used by UAT-7810 to host malicious payloads for a variety of hardware platforms including MIPS, ARM, and x64. The malware hosted predominantly consists of DOGLEASH, and accompanying shell scripts are executed on compromised systems to download and execute DOGLEASH.

All three of the following IP addresses were associated with VPS instances that indicated UAT-7810 acquired and used these servers as download locations:

  • 194.233.92[.]26
  • 217.15.160[.]247
  • 217.15.164[.]147

 One of the IPs, “217.15.164[.]147”, was also used as infrastructure to conduct exploitation of ASUS’ AiCloud Routers in early 2026 — specifically CVE-2025-2492 — indicating that UAT-7810 or an associated threat actor likely attempted to expand their ORB network to AiCloud Routers.

Additionally, “217.15.160[.]247” and “217.15.164[.]147”,  hosted a TLS server on port 99 with the certificate fingerprint:

c2ab9adaba93ff094b8f3fc37d906014d870582039d276b7bd03e6fd583d8a15
and
subject_dn = "C=exploit, ST=exploit, L=exploit, O=exploit, OU=exploit, CN=exploit"

Forensic analysis of compromised networking devices led to the discovery of a fourth IP address UAT-7810 used to host their malicious payloads: “95.182.100[.]231”, residing in Hong Kong.

UAT-7810's malware suite

LONGLEASH: A new version of SHORTLEASH

LONGLEASH is a new version of UAT-7810's previously disclosed backdoor SHORTLEASH. SHORTLEASH consisted of a backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels, and acting as both a C2 server and client. LONGLEASH, however, contains a variety of additional capabilities, indicating that UAT-7810 is actively developing it for use against their targets.

LONGLEASH is built off the same codebase as SHORTLEASH, with both tools being internally named “ff-agent”. The LONGLEASH variant compiled for MIPS processors is built on the asynchronous version of the Boost library (Boost.Asio) to minimize the blocking time and maximize the performance of the network.

The internal name for the LONGLEASH project is “nz1.0” and it has the following major components:

  • Base: Contains the implant’s logging and utilities, such as routines for Base58 and Base64 encoding and decoding.
  • Executor: Supports several capabilities, including the main proxying functions, for setting up the following channels:
    • Reverse shell to C2
    • Proxy servers for HTTP, DNS, SOCKS, TCP, ICMP, and UDP
    • Packet redirection for traffic based on TCP, UDP, and HTTP
    • SMTP server and client

The other major executor modules support managing of network connections to other servers, including TLS and public key infrastructure, managing clients connected to the implant, sockets and URIs.

 The executor is also tasked with authorization of clients, routing of the messages through the proxy network, and setting and management of basic network tunnels.

 Finally, the executor contains functionality to remove the implant and all traces from the server if a suspicious connection or tampering is detected.

  • Core: Provides basic authorization and node identification services, HTTP encoding and utilities, processing of protocol buffer (protobuf) encoded messages, basic SHA checksum functions, task management, and basic security.

The implant contains the User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.95 Safari/537.36" which may allow it to hide within legitimate traffic purporting to be an instance of the Windows Chrome version 122.

 Apart from the Boost.Asio, the implant contains code from at least two open-source libraries: Nanopb, used for processing protobuf messages, and MbedTLS, for establishing TLS, proxying TLS encrypted communications, and managing x509 certificates for the network. The implant does not use a standard libc library but a small musl library libc that implements C functions on top of Linux syscalls.

LONGLEASH also has the capability to act as an intermediate C2 server. It can obtain commands and data from the original C2 and forward to its peers.

UAT-7810 continues building ORB networks using new malware
Figure 1. LONGLEASH’s functional components.

DOGLEASH: The passive backdoor

Talos also discovered a previously unknown backdoor, developed and operated by UAT-7810, that we track as DOGLEASH. After compromising a networking device, UAT-7810 deploys a shell script that:

  1. Downloads DOGLEASH.
  2. Adds iptables rules to allow TCP traffic to a specific port, on which DOGLEASH binds and listens.
  3. Executes DOGLEASH on the device.
UAT-7810 continues building ORB networks using new malware

Key Takeaways

  • UAT-7810 continues building ORB networks using new malware — Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their...
  • High-severity alert: organizations should assess their exposure and apply mitigations promptly.
  • Staying informed on emerging threats is key to maintaining a strong security posture.
  • Immediate investigation and remediation are recommended based on the severity of this threat.
☕ Buy a Coffee