CVE Tools
Back to feed
Research Ruckus wireless routers UAT-7810 nation-state ASUS AiCloud routers UAT-5918

UAT-7810 continues building ORB networks using new malware

Cisco Talos·By Jungsoo An··8 min read
CVE Tools coverage

Cisco Talos reports that the China-nexus APT actor UAT-7810 continues expanding LapDogs Operational Relay Box (ORB) networks, adding new malware capabilities to support follow-on attacks on high-value targets. The actor is developing an updated version of SHORTLEASH tracked as LONGLEASH and has introduced additional backdoors including DOGLEASH and the Java-based JARLEASH for remote administration. Talos also observed UAT-7810 exploiting unpatched Ruckus wireless routers using CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, underscoring the risk of ORB-based persistence and device compromise when these vulnerabilities remain unremediated.

Tuesday, July 7, 2026 06:00

  • Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025.
  • UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets.
  • Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware, dubbed “SHORTLEASH,” with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as “LONGLEASH.”
  • Furthermore, we’ve discovered two new malware families in UAT-7810's arsenal: a C-based backdoor we track as “DOGLEASH” and a JAVA-based backdoor we track as “JARLEASH.”…
Continue reading on Cisco Talos