logo

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

ID: 5b209bff-114d-5e0c-ac60-5850c55b1c3a

STIX ID: report--5b209bff-114d-5e0c-ac60-5850c55b1c3a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Cisco Talos attributes a Chinese APT tracked as UAT-7810 with actively refining and deploying bespoke malware (ShortLeash and its successor LONGLEASH) and auxiliary tools (DOGLEASH, LEASHTEST, JARLEASH) to compromise internet-facing routers and build an Operational Relay Box (ORB) network (LapDogs); campaigns exploit known router CVEs (Ruckus, ASUS) to provide C2, proxying/relay functionality, and persistent access that can be leveraged by secondary actors against high-value targets, including critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.