Recently, cybersecurity researchers identified a sophisticated threat actor from China, designated as UAT-7810, which is intensifying its operations to enhance its Operational Relay Box (ORB) network by infiltrating network devices that are accessible over the internet. This revelation comes from an analysis conducted by Cisco Talos, a reputable threat intelligence group.
UAT-7810 falls into the category of advanced persistent threat (APT) groups and has been linked to the development and maintenance of an ORB network known as LapDogs, which gained attention in June 2025 for its extensive operational capacity. Experts suggest that the primary objective of UAT-7810 is to set up these ORB networks to facilitate secondary threat actors in launching cyberattacks targeting high-value assets and sectors.
Among those utilizing this infrastructure is another Chinese-linked actor, UAT-5918. This group has been implicated in cyber operations against critical infrastructure in Taiwan, aiming to establish enduring access within vulnerable environments since at least 2023.
Recent analysis indicates that UAT-7810 is not standing still. It has progressed its specialized malware known as ShortLeash and introduced a more advanced version referred to as LONGLEASH. Additionally, two previously unreported tools have surfaced: DOGLEASH, which functions as a passive backdoor on compromised Linux systems, and LEASHTEST, a testing utility aimed at examining functionality within MIPS-based embedded devices.
The researchers noted that UAT-7810 has deployed at least four new servers to host various iterations of DOGLEASH for targeting compromised systems. A Java-based backdoor identified as JARLEASH was also found on at least one server, enabling administrative tasks such as file management and facilitating FTP and SFTP communications.
The threat actor exploits weaknesses within unpatched Ruckus wireless routers, with campaigns leveraging several critical vulnerabilities like CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. There have also been recent attempts to compromise ASUS AiCloud Routers, underscoring a commitment to broaden the ORB network.
ShortLeash is equipped with extensive capabilities that allow it to act as both a command-and-control server and a client, showing its dual functions in communicating with external servers. The successor, LONGLEASH, takes this further by providing a range of advanced features, including network connection management and authorization of client requests, while also obscuring evidence of its presence should it detect any unauthorized tampering.
The emergence of LEASHTEST indicates that UAT-7810 continues to rigorously test and refine its functionalities on MIPS platforms, suggesting a deliberate focus on ensuring the reliability of their evolving backdoor infrastructures. This operational flexibility raises significant concerns regarding the group’s ongoing intent and capacity for future cyberattacks.
In conclusion, the findings present a clear image of a sophisticated and evolving threat landscape, especially for organizations relying on vulnerable networking devices. Understanding the potential tactics and techniques used in these breaches, not least those outlined by the MITRE ATT&CK Framework—including initial access methods, persistence strategies, and privilege escalation maneuvers—will be vital for businesses aiming to mitigate risk and bolster their cybersecurity postures.