Bleepingcomputer UAT-7810 Expands Malware Arsenal to Enhance ORB Network
Article Content
- •UAT-7810 is developing LONGLEASH, an advanced version of its SHORTLEASH backdoor.
- •The group exploits vulnerabilities in Ruckus and ASUS routers to expand its ORB network.
- •New malware tools include DOGLEASH for Linux and JARLEASH for server management.
The China-linked threat actor UAT-7810 is evolving its malware toolkit, notably introducing LONGLEASH, an upgraded version of the SHORTLEASH backdoor. This group exploits known vulnerabilities in unpatched Ruckus routers and recently began targeting ASUS AiCloud routers. The malware facilitates the creation of an Operational Relay Box (ORB) network, allowing other APTs to mask their traffic. Talos has identified multiple CVEs exploited by UAT-7810, including CVE-2020-22653, CVE-2020-22658, and CVE-2025-2492. The group has also developed additional tools like DOGLEASH, a Linux backdoor, and JARLEASH, a Java-based administrative tool. The ongoing activity indicates a significant threat to organizations using the affected devices. The group’s tactics rely on exploiting unpatched vulnerabilities, which remain a low-effort yet effective attack vector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Uat-7810, Dogleash and Asus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…