A China-linked advanced persistent threat (APT) actor has been updating its arsenal with new backdoors, allowing it to more effectively spy on targets and compromise their systems. The group, tracked as UAT-7810 by Cisco’s Talos researchers, has infected over 1,000 small office/home office (SOHO) routers with a malicious backdoor known as LongLeash.
This is part of a broader espionage infrastructure campaign dubbed LapDogs, which targets vulnerabilities in Ruckus wireless routers and allows the attackers to download payloads for multiple architectures, including MIPS, ARM, and x64. The group has also been seen using two other malware families: DogLeash and JarLeash. These backdoors provide UAT-7810 with a range of capabilities, including command-and-control (C&C) communication, web server hosting, tunnel management, and the ability to act as both C&C and client.
One of the most concerning aspects of this campaign is its use of intermediate servers to forward commands and data received from the C&C to other peers. This allows the attackers to create a complex network of compromised systems, making it difficult for defenders to track their activities. The LongLeash backdoor also contains code from open source libraries such as Nanopb and MbedTLS, highlighting the group’s ability to adapt and improve its tools.
The UAT-7810 group has been linked to another China-linked APT, UAT-5918, which shares some of the same tooling. However, they are still tracked as separate groups due to their distinct tactics and objectives. This raises questions about the level of coordination between these groups and whether they are working together to achieve common goals.
The discovery of LongLeash and the other malware families used by UAT-7810 highlights the ongoing threat posed by China-linked APTs. These groups continue to evolve and improve their tools, making it essential for defenders to stay vigilant and adapt to new threats. The use of backdoors like LongLeash also underscores the importance of patching vulnerabilities in network devices and keeping software up-to-date.
In practical terms, this means that users should take immediate action to secure their SOHO routers and other network devices. This includes applying patches for known vulnerabilities, changing default passwords, and implementing robust security measures such as intrusion detection and prevention systems (IDPS). By staying ahead of the threats posed by groups like UAT-7810, defenders can reduce the risk of compromise and protect sensitive data from falling into the wrong hands.
Source: SecurityWeek — 2026-07-08