logo

China-Linked APT Expands Proxy Network With New Malware

ID: 9a1dab5f-b148-5231-ab39-a0bc963349aa

STIX ID: report--9a1dab5f-b148-5231-ab39-a0bc963349aa

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

...
...

Cisco Talos attributes a China-linked APT (UAT-7810) with operating a large ORB relay network called LapDogs that hijacks routers and edge devices—using known but unpatched Ruckus and ASUS vulnerabilities—to provide proxy infrastructure for other espionage actors. Talos uncovered active custom tooling (LONGLEASH backdoor with proxying, DOGLEASH for Linux, JARLEASH Java server-management tool) and development artifacts for MIPS devices, indicating ongoing refinement and active servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.