CVE Tools
Back to feed
Incident UAT-7810 malware UAT-5918 nation-state

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Cisco Talos reports that the China-linked threat actor UAT-7810 is extending its Operational Relay Box (ORB) network by improving its custom malware, including an updated version of ShortLeash dubbed LONGLEASH along with new tools DOGLEASH and LEASHTEST. The campaign targets internet-facing networking gear, leveraging known issues in Ruckus wireless routers tied to CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, and also points at ASUS AiCloud Routers affected by CVE-2025-2492. This matters because ORB expansion can help secondary attackers gain infrastructure for further intrusion and exploitation against high-value targets.