UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492) — Threadlinqs Intelligence
As of 2026-07-13, UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492) is a high-severity malware threat attributed to UAT-7810 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1257 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: MALWARE
Attribution: UAT-7810 · China · ESPIONAGE
China-nexus APT actor UAT-7810 continues building Operational Relay Box (ORB) networks — including the long-running LapDogs ORB — for use by secondary Chinese threat actors such as UAT-5918,
UAT-7810 is a China-nexus threat actor assessed to operate as an infrastructure provider — building and maintaining Operational Relay Box (ORB) networks that are subsequently leveraged by other China-aligned APT groups, notably UAT-5918, to proxy attack traffic against high-value targets (including Taiwanese critical infrastructure) while evading attribution. The group maintains the long-running LapDogs ORB network, first disclosed in 2025, and continues to expand it by compromising internet-facing, unpatched embedded network devices.
Initial access is achieved by exploiting n-day vulnerabilities in Ruckus wireless Access Point/router firmware (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 — an unauthenticated RCE via crafted HTTP GET request in Ruckus Wireless Admin through 10.4, CVSS 9.8) and, as of early 2026, ASUS AiCloud routers (CVE-2025-2492 — an improper authentication control / CWE-288 flaw allowing remote, unauthenticated bypass of AiCloud authentication, CVSS 9.2). Post-exploitation, the actor deploys shell scripts that configure iptables rules and then download and execute the group's custom malware.
The malware arsenal has expanded significantly since the original SHORTLEASH backdoor. LONGLEASH (Talos-observed internal build name 'nz1.0') is a next-generation rewrite built on the SHORTLEASH codebase using the Boost.Asio library for asynchronous networking; it adds reverse shell functionality, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxying and packet redirection, SMTP client/server capability, TLS/PKI integration, self-deletion on detection of suspicious analysis activity, and the ability to act as an intermediate C2 relay node between compromised devices and downstream operators. DOGLEASH is a newly-identified C-based passive backdoor for Linux that listens on a hardcoded port, uses password-based command decoding, spawns a thread per received command, supports remote command execution via /bin/sh, file read/backup operations, OS/hardware fingerprinting, and in-memory shellcode execution; it has been cross-compiled for MIPS, MIPS32r2, ARMv7, MIPS1, MIPS32r2el, and MIPS32el architectures, reflecting the broad range of embedded router/IoT hardware targeted. JARLEASH is a newly-identified Java-based (JAR) backdoor deployed for hands-on administrative access on at least one C2 server, providing a web-based file manager, FTP/SFTP server hosting, and Netcat server deployment; JARLEASH kills existing malware instances before spawning new processes, and its configuration files contain Simplified Chinese-language comments, reinforcing Chinese-speaking operator attribution. LEASHTEST is a non-malicious ELF test binary for the MIPS platform used to validate thread creation/joining, TCP port binding, process spawning, async timers, and exception handling prior to full malware deployment — its presence on a device is itself an indicator of compromise and shows UAT-7810 is still actively validating tooling on MIPS-based embedded targets.
UAT-7810 operates at least four attacker-controlled C2/hosting servers (194.233.92.26, 217.15.160.247, 217.15.164.147, and 95.182.100.231 — the last geolocated to Hong Kong), each exposing consistent ports 2222, 8088, and 99, used for DOGLEASH C2 hosting and TLS-terminated communications. The infrastructure shares a distinctive self-signed TLS certificate with subject/issuer fields deliberately set to the literal string 'exploit' across all DN fields (C=exploit, ST=exploit, L=exploit, O=exploit, OU=exploit, CN=exploit) — a notable operational fingerprint. 217.15.164.147 was specifically observed being used for the ASUS AiCloud (CVE-2025-2492) exploitation activity. Malware samples masquerade network traffic using a browser user-agent string and encode payloads with Base58/Base64 and Protocol Buffer (protobuf) serialization; the toolset relies on Boost.Asio, Nanopb, MbedTLS, and musl libc.
Talos assesses UAT-7810's role as most likely that of an ORB infrastructure provider tasked with building relay
Weaknesses (CWE)
CWE-288, CWE-78, CWE-306
Target sectors: government administration, critical-infrastructure, telecoms, consumer-networking
Target regions: taiwan, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
7 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492, T1190, T1587.001, T1583.004, T1584.005, T1059.004, T1106, T1505, T1070.004, T1027, T1620