Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese Hackers Expand Sophisticated ORB Network with New Malware Capabilities

A highly advanced Chinese hacking group, tracked as “UAT-7810,” has been quietly expanding its Operational Relay Box (ORB) network by compromising internet-facing networking devices. The hackers are using a new malware called LONGLEASH to gain access and control over these devices, which serve as secure relay infrastructure for other China-aligned advanced persistent threats (APTs).

The ORB network is a critical component of the hacking group’s operations, allowing them to proxy their network traffic through regional devices. This makes it appear as though the traffic originates from legitimate local infrastructure, making it difficult for security teams to detect and attribute the attacks. The hackers are also using other malware tools, including DOGLEASH, JARLEASH, and LEASHTEST, which provide additional capabilities for compromising and controlling devices.

The LONGLEASH malware is an upgraded version of SHORTLEASH, a backdoor that was first documented in 2025. It has significantly expanded its capabilities to include reverse shell support, HTTP, DNS, SOCKS, TCP, ICMP, and UDP proxying with traffic redirection, SMTP client/server functionality, TLS and PKI support, and self-removal when tampering or suspicious activity is detected.

The hackers are primarily exploiting known (n-day) vulnerabilities in Ruckus routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. They are also targeting ASUS AiCloud routers with the vulnerability CVE-2025-2492.

The use of LONGLEASH and other malware tools by UAT-7810 is a clear indication that these hackers are committed to expanding their ORB infrastructure and increasing their capabilities for future attacks. The fact that they are using known vulnerabilities to gain initial access also highlights the importance of keeping devices up-to-date with the latest security patches.

The expansion of the ORB network and the development of new malware tools by UAT-7810 pose a significant threat to organizations worldwide. It is essential for security teams to be aware of these developments and take proactive steps to protect their networks and systems from these types of attacks.

To mitigate this risk, organizations should prioritize patching their devices, including routers and other internet-facing equipment, as soon as possible. They should also implement robust monitoring and detection tools to identify any suspicious activity on their networks. Additionally, regular security audits and penetration testing can help identify vulnerabilities and weaknesses in their systems, allowing them to take corrective action before it’s too late.

Ultimately, the ongoing expansion of the ORB network by UAT-7810 serves as a reminder that cybersecurity threats are constantly evolving, and organizations must remain vigilant and proactive in their defense efforts.


Source: Bleeping Computer — 2026-07-07