CVE Tools
Back to feed
Exploited in the wild Ruckus wireless routers UAT-7810 ics-ot-iot Asus AiCloud Routers Ruckus

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

A China-linked APT group, tracked as UAT-7810, has expanded its toolkit with new backdoor variants targeting SOHO routers from Ruckus and Asus. Researchers at Cisco Talos have uncovered updated malware families—LongLeash, DogLeash, and JarLeash—that exploit known vulnerabilities such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. These tools enable attackers to maintain persistent access, manage tunnels, and execute remote commands. The threat actor is also linked to a broader espionage campaign involving thousands of compromised devices.