A Chinese threat actor tracked as UAT-7810 keeps building out its relay network. The group is actively refining custom malware to break into internet-facing networking devices and expand their Operational Relay Box (ORB) infrastructure.
Cisco Talos tracks this APT group. They’re responsible for LapDogs, an ORB network that surfaced in June 2025. The idea? Set up relay boxes that secondary threat actors can then use to launch their own attacks against high-value targets. One known customer is UAT-5918, which has been hitting critical infrastructure in Taiwan since at least 2023.
The latest findings show UAT-7810 has been busy developing. Their custom ShortLeash malware now has a newer version called LONGLEASH. It packs a lot more functionality than its predecessor — proxying over HTTP, DNS, SOCKS, TCP, ICMP, and UDP protocols, managing network connections, authorizing clients, even self-destructing if it detects tampering.
Two other tools also showed up: DOGLEASH, a passive backdoor that runs arbitrary shellcode on compromised Linux devices, and LEASHTEST, a testing binary for MIPS-based embedded devices. Talos also spotted JARLEASH, a Java-based backdoor used for file management, FTP, SFTP, and Netcat operations.
The group targets unpatched routers. Known exploited vulnerabilities include flaws in Ruckus wireless routers and ASUS AiCloud routers. Recent campaigns have targeted ASUS devices vulnerable to a 2025 bug, suggesting the group is trying to broaden its reach.
The fact that they’re still testing on MIPS platforms with LEASHTEST suggests they’re not fully confident LONGLEASH behaves correctly on those devices yet. But the active development cycle is clear — this group isn’t slowing down.
