logo

Chinese hackers develop LONGLEASH malware to expand ORB network

ID: 7a481855-6da6-5798-921e-a4078820665d

STIX ID: report--7a481855-6da6-5798-921e-a4078820665d

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

UAT-7810, a China-aligned actor, is actively expanding an ORB relay infrastructure by exploiting known vulnerabilities in internet-facing routers (including Ruckus and ASUS devices) and deploying upgraded toolsets—LONGLEASH (an enhanced backdoor/proxy/C2), DOGLEASH (Linux backdoor), JARLEASH (Java admin tool), and LEASHTEST (MIPS testing utility)—to proxy traffic, evade detection, and support other regional APT operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.