logo

Gonzo threat hunting: LapDogs & ShortLeash

ID: 13e94991-0c3b-5c5f-9cd8-07474c7bb4d3

STIX ID: report--13e94991-0c3b-5c5f-9cd8-07474c7bb4d3

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2025-09-24

Date Updated: 2026-04-27

Author: Malachi Woodlee

...
...

Using Censys and internal log hunts, analysts identified an ORB (Operational Relay Box) campaign called 'LapDogs' that deploys a ShortLeash backdoor to compromise SOHO devices (notably routers) and proxy traffic through nodes presenting spoofed self-signed TLS certificates claiming the LAPD; the report includes IOCs (specific cert DN, C2 HTTP GET patterns on ephemeral ports with short hex responses, and a long list of IPs/ASNs), notes suspected Chinese attribution, documents customer exposures (passive data leakage), and recommends patching SOHO devices and monitoring/blocking the provided indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.