China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
ID: 5b209bff-114d-5e0c-ac60-5850c55b1c3a
STIX ID: report--5b209bff-114d-5e0c-ac60-5850c55b1c3a
Feed Name: The Hacker News
Cisco Talos attributes a Chinese APT tracked as UAT-7810 with actively refining and deploying bespoke malware (ShortLeash and its successor LONGLEASH) and auxiliary tools (DOGLEASH, LEASHTEST, JARLEASH) to compromise internet-facing routers and build an Operational Relay Box (ORB) network (LapDogs); campaigns exploit known router CVEs (Ruckus, ASUS) to provide C2, proxying/relay functionality, and persistent access that can be leveraged by secondary actors against high-value targets, including critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
