logo

LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities

ID: b9e8a60f-0776-5b40-9bd7-2fb01d24c1d1

STIX ID: report--b9e8a60f-0776-5b40-9bd7-2fb01d24c1d1

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

**Executive summary:** Cisco Talos documents a significant upgrade to the UAT-7810 actor's implant—LONGLEASH—which evolves SHORTLEASH into a modular, multi-architecture implant capable of reverse shells, multi-protocol proxying, and acting as an intermediate C2/relay (ORB) node; the report also details additional tools (DOGLEASH, JARLEASH), exploited router/IoT CVEs used for initial access, infrastructure IPs and cert fingerprints, and detection/mitigation guidance including IDS signatures and hunting recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.