The Chinese-origin threat actor UAT-7810 is stepping up its activities, developing new sophisticated malware aimed at expanding the Operational Relay Box (ORB) it manages. According to new findings from Cisco Talos, UAT-7810 has upgraded its arsenal with a new tool codenamed LONGLEASH, a successor to the older ShortLeash. The group primarily targets network devices exposed to the internet, exploiting known vulnerabilities in routers and other networking equipment.

UAT-7810 is a Advanced Persistent Threat (APT) responsible for the creation and management of LapDogs, an ORB network that was discovered in June 2025. According to researchers Jungsoo An, Asheer Malhotra, Vanja Svajcer , and Brandon White, UAT-7810 is likely tasked with creating ORB networks that are then leveraged by secondary threat actors to attack high-value targets. One such actor is UAT-5918, which has been linked to cyberattacks against critical infrastructure in Taiwan since at least 2023 (with the goal of establishing persistent access to victims' environments).
See also: Chinese UAT-8302 hackers target governments with custom malware
UAT-7810: New LONGLEASH malware and expansion of the ORB network
The new LONGLEASH is an advanced version of ShortLeash and incorporates additional features that indicate an active development cycle. ShortLeash already had the ability to communicate with an external server, host a web server, and act as a command-and-control (C2) server and client at the same time. LONGLEASH adds an executor component that allows proxying via HTTP, DNS, SOCKS, TCP, ICMP, and UDP, manages network connections, authorizes clients, and removes the implant along with all its traces from the server (if any attempted breach is detected).
In addition to LONGLEASH, UAT-7810 has developed two more tools that have not been reported to date. The first is DOGLEASH, a passive backdoor capable of executing arbitrary shellcode on compromised Linux. The second is LEASHTEST, an ELF binary used to test specific functions on devices based on the MIPS. The existence of LEASHTEST suggests that, despite the development of the full LONGLEASH, the team is still testing functions on MIPS platforms and may not be completely sure of the behavior of the malware on these devices.
Additionally, Cisco Talos detected a Java-based backdoor called JARLEASH, which was deployed by UAT-7810 on at least one of the three servers for administrative purposes, including file management, FTP, SFTP , and Netcat. UAT-7810 used at least four new servers to host variants of DOGLEASH and deploy them against compromised targets, demonstrating the operational maturity of the group.
See also: Gaslight: New macOS Malware with Prompt Injection against AI Tools

UAT-7810: Exploiting vulnerabilities in Ruckus and ASUS routers
The UAT-7810 attack chains are based on exploiting known vulnerabilities in unpatched networking devices. Specifically, the group has targeted Ruckus wireless routers by exploiting vulnerabilities CVE-2020-22653, CVE-2020-22658 , and CVE-2023-25717. More recently, some attacks have targeted ASUS AiCloud Routers that are vulnerable to CVE-2025-2492, suggesting possible attempts to expand the ORB network to new categories of devices. The choice of these targets is not accidental: networking devices located at the perimeter of organizations are ideal entry points, as they are often not monitored with the same rigor as user endpoints.
The ORB network managed by UAT-7810 acts as a relay infrastructure for other APT actors of Chinese origin. LONGLEASH acts as an intermediate C2 server, relaying commands and data from the main C2 to its peers. This architecture makes it extremely difficult to perform attacks and detect the attackers' real infrastructure, as the traffic appears to come from legitimate compromised devices and not from servers directly controlled by the attackers.
See also: SharkLoader: New malware disguises itself as Cisco and Google updates
To protect against UAT-7810-type threats, organizations should immediately apply security updates to all networking devices, especially Ruckus and ASUS routers. Monitoring network traffic for abnormal communication patterns via protocols such as ICMP and DNS is also critical. In addition, network segmentation and strict access policies on perimeter devices can significantly reduce exposure. According to The Hacker News, the UAT-7810 activity is a typical example of the evolving Chinese cyberespionage targeting critical infrastructure worldwide.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
