logo

Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign

ID: fb45c8ec-b4dc-5457-a872-54beb572f577

STIX ID: report--fb45c8ec-b4dc-5457-a872-54beb572f577

Feed Name: SecurityScorecard Blog

Threat Score
88/100

Date Published: 2025-12-11

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE team uncovered a previously unreported China-linked ORB network dubbed "LapDogs," using a custom backdoor called ShortLeash to create an extensive covert espionage infrastructure of over 1,000 active nodes across the U.S. and Southeast Asia; the campaign targets SOHO devices, uses self-signed TLS certs labeled "LAPD" for obfuscation, operates in methodical regional waves since at least September 2023, and is assessed to have been used by APT UAT-5918.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.