A China-aligned hacking group is expanding a covert relay network by breaking into internet-facing routers and loading new backdoor malware. Cisco Talos says UAT-7810 is using LONGLEASH, plus DOGLEASH, JARLEASH, and LEASHTEST, to grow an operational relay box (ORB) infrastructure that can proxy traffic for other China-linked actors. Initial access relies on n-day flaws in Ruckus routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492).
Why it matters: Organizations and consumers with unpatched edge devices could have their routers turned into stealth infrastructure for espionage or follow-on attacks. Patch affected Ruckus and ASUS devices, check Talos indicators of compromise, and review exposed networking gear for web shells, tunneling, and unusual proxy behavior.
Ionut Arghire
2026.07.08
97% relevant
This article is a direct update on the same UAT-7810 router-compromise campaign, adding detail that Talos observed new Leash-family backdoors including LongLeash, DogLeash, and JarLeash, plus continued exploitation of Ruckus flaws CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 and infrastructure overlap with ASUS AiCloud targeting in Operation WrtHug.
Bill Toulas
2026.07.07
100% relevant
This article establishes a distinct campaign centered on UAT-7810's LONGLEASH malware and the expansion of a China-aligned ORB router network, not the same underlying event as the existing JDY, Calypso, Earth Lusca, or UNC6508 stories.
← Back to all stories