LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
ID: b9e8a60f-0776-5b40-9bd7-2fb01d24c1d1
STIX ID: report--b9e8a60f-0776-5b40-9bd7-2fb01d24c1d1
Feed Name: GBHackers
**Executive summary:** Cisco Talos documents a significant upgrade to the UAT-7810 actor's implant—LONGLEASH—which evolves SHORTLEASH into a modular, multi-architecture implant capable of reverse shells, multi-protocol proxying, and acting as an intermediate C2/relay (ORB) node; the report also details additional tools (DOGLEASH, JARLEASH), exploited router/IoT CVEs used for initial access, infrastructure IPs and cert fingerprints, and detection/mitigation guidance including IDS signatures and hunting recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
