Particle.news
Download on the App Store

China-Linked UAT-7810 Builds Out Router Relay Network With New LONGLEASH Backdoor

An upgraded backdoor plus testing tools broaden the group’s router relay capacity to make attacks harder to detect and attribute.

Overview

  • Cisco Talos says UAT-7810 is actively expanding an Operational Relay Box (ORB) network by compromising unpatched, internet-facing routers to create a relay layer other attackers can use.
  • Researchers found a new backdoor called LONGLEASH that adds reverse-shell access, multi-protocol proxying (HTTP, DNS, SOCKS, TCP, ICMP, UDP), SMTP client/server, TLS/PKI support, self-removal, and the ability to act as an intermediate command-and-control relay.
  • The actor gains initial access mainly by exploiting known n-day flaws in Ruckus routers (including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and an ASUS AiCloud bug (CVE-2025-2492), rather than relying on fresh zero-days.
  • Talos also identified supporting tools—DOGLEASH (Linux backdoor), JARLEASH (Java admin tool), and LEASHTEST (a test utility)—with LEASHTEST used to validate behavior on MIPS-based embedded devices.
  • Coverage on Wednesday, July 8, 2026 shows the campaign is ongoing and that expanding ORB coverage to more device types could let other China-aligned APTs route operations through compromised routers to obscure origin and complicate detection.