China-Nexus APT UAT-7810 Expands ORB Network with New Malware and Exploits
Cisco Talos reports on APT actor UAT-7810, which continues to develop and deploy custom malware, including new backdoors LONGLEASH, DOGLEASH, and JARLEASH, exploiting n-day vulnerabilities to build Operational Relay Box (ORB) networks.

Cisco Talos is tracking the activities of UAT-7810, an advanced persistent threat (APT) actor known for establishing and maintaining the LapDogs Operational Relay Box (ORB) network. First disclosed in 2025, this network is believed to be leveraged by secondary threat actors for conducting malicious attacks against high-value targets. Talos's latest analysis reveals that UAT-7810 is actively developing its custom malware, with a new version of its SHORTLEASH backdoor, now tracked as LONGLEASH, already deployed on attacker-controlled infrastructure. Furthermore, the actor has expanded its arsenal with two new malware families: DOGLEASH, a C-based backdoor for Linux, and JARLEASH, a Java-based backdoor.
Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor, evidenced by the infrastructure it provides to other China-nexus APTs such as UAT-5918. While open-source reporting indicates overlapping tooling between these two groups, Talos considers them separate entities with distinct objectives. The continuous development of malware like LONGLEASH, which builds upon the capabilities of SHORTLEASH, demonstrates UAT-7810's commitment to evolving its toolkit for persistent access and control.
Among the newly discovered tools is DOGLEASH, a backdoor capable of executing arbitrary shellcode on compromised Linux devices. Another utility, LEASHTEST, is a Linux binary designed for testing basic functionality on MIPS-based embedded devices. UAT-7810 has also been observed using multiple new servers to host variations of DOGLEASH, deploying them against compromised targets. The actor has also deployed JARLEASH, a Java-based backdoor, for administrative tasks including file management, FTP, SFTP, and Netcat operations.
A significant aspect of UAT-7810's operations involves exploiting known, unpatched vulnerabilities, particularly in Ruckus wireless routers. This tactic has been employed since 2025, with recent exploitation attempts targeting CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. The actor has also been observed exploiting CVE-2025-2492 in ASUS AiCloud Routers, indicating an effort to broaden the reach of their ORB network to different hardware platforms.
Talos identified four new servers used by UAT-7810 to host malicious payloads for various hardware architectures, including MIPS, ARM, and x64. These servers primarily hosted DOGLEASH, with accompanying shell scripts facilitating its execution on compromised systems. The IP addresses associated with these servers include 194.233.92[.]26, 217.15.160[.]247, and 217.15.164[.]147. Notably, one of these IPs was also used for exploiting ASUS AiCloud Routers, suggesting a potential expansion of the ORB network.
The LONGLEASH backdoor, an evolution of SHORTLEASH, offers enhanced capabilities. Both tools share the internal name "ff-agent." The MIPS-compiled variant of LONGLEASH utilizes the asynchronous Boost.Asio library for improved network performance. Its internal project name is "nz1.0," and it comprises several key components: Base (logging, encoding/decoding utilities), Executor (proxying functions, reverse shells, various proxy server types, packet redirection, SMTP server/client, network connection management, client authorization, and implant removal), and Core (authorization, node identification, HTTP encoding, and protobuf processing).
The expanded capabilities of LONGLEASH, coupled with the introduction of DOGLEASH and JARLEASH, highlight UAT-7810's ongoing efforts to refine its toolkit for sophisticated cyber operations. By exploiting n-day vulnerabilities in widely used network devices, the actor continues to build and expand its ORB infrastructure, posing a persistent threat to organizations globally.
This latest report from BleepingComputer details the specific targeting of unpatched Ruckus routers by UAT-7810, highlighting the deployment of the new LONGLEASH malware. The article emphasizes how this malware is used to expand the threat actor's existing ORB network, focusing on gaining persistent access through compromised internet-facing devices.
This latest report from Cyber Security News details the ongoing expansion of the LapDogs ORB network by China-nexus threat actor UAT-7810. The group is now deploying an upgraded backdoor named LONGLEASH, which offers enhanced capabilities over its predecessor, SHORTLEASH. Additionally, the report highlights the discovery of two new tools, DOGLEASH and JARLEASH, further expanding the actor's toolkit for maintaining persistent access and relaying traffic through compromised Ruckus routers and potentially ASUS AiCloud devices.
This latest report from The Hacker News details the emergence of LONGLEASH, a successor to the previously identified ShortLeash malware, which incorporates enhanced executor capabilities for proxying various network protocols and improved C2 relay functions. Additionally, the article highlights the deployment of two new tools, DOGLEASH (a passive backdoor for Linux) and LEASHTEST (an ELF binary for testing MIPS embedded devices), alongside a Java-based backdoor named JARLEASH, further expanding UAT-7810's arsenal.
The new reporting details the specific methods UAT-7810 uses to expand its Operational Relay Box (ORB) network, including exploiting unpatched vulnerabilities in Ruckus wireless routers since 2025 and ASUS routers earlier this year. Furthermore, the article introduces three new custom malware tools developed by the group: LONGLEASH, an upgraded backdoor with proxying capabilities; DOGLEASH, for executing commands on Linux devices; and JARLEASH, a Java-based server management tool, with JARLEASH's configuration file containing comments in Simplified Chinese.
Cisco Talos has identified three new backdoors—LongLeash, DogLeash, and JarLeash—used by the China-linked APT actor UAT-7810, expanding its arsenal beyond the previously reported ShortLeash. These new tools, including a Java-based backdoor and a C-based passive backdoor, offer enhanced capabilities for espionage and maintaining operational relay box (ORB) networks. The actor continues to exploit known vulnerabilities in SOHO routers, particularly Ruckus devices, and has been observed using infrastructure also implicated in the Operation WrtHug campaign.