Incident UAT-7810 malware UAT-5918 nation-state
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
CVE Tools coverage
Cisco Talos reports that the China-linked threat actor UAT-7810 is extending its Operational Relay Box (ORB) network by improving its custom malware, including an updated version of ShortLeash dubbed LONGLEASH along with new tools DOGLEASH and LEASHTEST. The campaign targets internet-facing networking gear, leveraging known issues in Ruckus wireless routers tied to CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, and also points at ASUS AiCloud Routers affected by CVE-2025-2492. This matters because ORB expansion can help secondary attackers gain infrastructure for further intrusion and exploitation against high-value targets.