Overview
- Cisco Talos says UAT-7810 is actively expanding an Operational Relay Box (ORB) network by compromising unpatched, internet-facing routers to create a relay layer other attackers can use.
- Researchers found a new backdoor called LONGLEASH that adds reverse-shell access, multi-protocol proxying (HTTP, DNS, SOCKS, TCP, ICMP, UDP), SMTP client/server, TLS/PKI support, self-removal, and the ability to act as an intermediate command-and-control relay.
- The actor gains initial access mainly by exploiting known n-day flaws in Ruckus routers (including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and an ASUS AiCloud bug (CVE-2025-2492), rather than relying on fresh zero-days.
- Talos also identified supporting tools—DOGLEASH (Linux backdoor), JARLEASH (Java admin tool), and LEASHTEST (a test utility)—with LEASHTEST used to validate behavior on MIPS-based embedded devices.
- Coverage on Wednesday, July 8, 2026 shows the campaign is ongoing and that expanding ORB coverage to more device types could let other China-aligned APTs route operations through compromised routers to obscure origin and complicate detection.