China-aligned UAT-7810 expands router-based ORB network with LONGLEASH malware on Ruckus and ASUS devices

A China-aligned hacking group is expanding a covert relay network by breaking into internet-facing routers and loading new backdoor malware. Cisco Talos says UAT-7810 is using LONGLEASH, plus DOGLEASH, JARLEASH, and LEASHTEST, to grow an operational relay box (ORB) infrastructure that can proxy traffic for other China-linked actors. Initial access relies on n-day flaws in Ruckus routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492).
Why it matters: Organizations and consumers with unpatched edge devices could have their routers turned into stealth infrastructure for espionage or follow-on attacks. Patch affected Ruckus and ASUS devices, check Talos indicators of compromise, and review exposed networking gear for web shells, tunneling, and unusual proxy behavior.

Sources

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Ionut Arghire 2026.07.08 97% relevant
This article is a direct update on the same UAT-7810 router-compromise campaign, adding detail that Talos observed new Leash-family backdoors including LongLeash, DogLeash, and JarLeash, plus continued exploitation of Ruckus flaws CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 and infrastructure overlap with ASUS AiCloud targeting in Operation WrtHug.
Chinese hackers develop LONGLEASH malware to expand ORB network
Bill Toulas 2026.07.07 100% relevant
This article establishes a distinct campaign centered on UAT-7810's LONGLEASH malware and the expansion of a China-aligned ORB router network, not the same underlying event as the existing JDY, Calypso, Earth Lusca, or UNC6508 stories.
← Back to all stories