Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese Hackers Expand Sophisticated ORB Network Using New Malware

A highly advanced and evolving threat actor group tracked as “UAT-7810” has been busy expanding their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. This malicious infrastructure allows China-aligned advanced persistent threats (APTs), including UAT-5918, to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure and evading detection.

The ORB network, first documented by Google Mandiant, serves as a secure relay infrastructure for various threat actors. It enables them to conceal the true origin of their attacks, complicating attribution efforts for cybersecurity researchers and defenders alike. The Talos analysts have identified new malware in this campaign, including LONGLEASH, an upgraded version of the SHORTLEASH backdoor, DOGLEASH, a Linux backdoor, JARLEASH, an administrative tool, and LEASHTEST, a testing utility.

The UAT-7810 group primarily exploits known (n-day) vulnerabilities to gain initial access. This includes CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers. By targeting unpatched devices, the attackers can establish a foothold in networks and gain access to sensitive information.

The newly discovered LONGLEASH malware is an upgraded version of SHORTLEASH, which significantly expands its capabilities. In addition to supporting command-and-control (C2) communications, web server hosting, network tunnel management, and operation as both a C2 server and client, the new malware has been observed with the following capabilities:

Reverse shell functionality

HTTP, DNS, SOCKS, TCP, ICMP, and UDP proxying with traffic redirection

SMTP client/server functionality

TLS and PKI support

Self-removal for when tampering or other suspicious activity is detected

Ability to act as an intermediate C2 server, forwarding commands and data between infected nodes

The presence of LONGLEASH in the ORB network further complicates the task of detecting and mitigating these threats. As the malware continues to evolve, cybersecurity teams must stay vigilant and ensure their networks are protected against known vulnerabilities.

Apart from LONGLEASH, the researchers have also discovered DOGLEASH, a lightweight Linux backdoor deployed via web shell scripts. Upon launch, it opens a listening TCP port and authenticates incoming requests using a hardcoded password, supporting shell command execution, file access and modification, OS information retrieval, and arbitrary code execution directly in the host’s memory.

The threat actors have also developed JARLEASH, a Java-based administrative tool that provides web-based file management and includes FTP, SFTP, and Netcat server functionality. Finally, LEASHTEST is used to verify whether an MIPS IoT device can perform functions related to malware operations, likely to help refine LONGLEASH’s MIPS support.

The UAT-7810 group’s continued expansion of their ORB infrastructure highlights the importance of prioritizing network security and ensuring that all devices are up-to-date with the latest patches. As cybersecurity teams log 54% of successful attacks and alert on just 14%, it is crucial to test every layer before attackers do.

To stay ahead of these threats, organizations should implement robust security measures, including regular vulnerability scanning and patch management. Additionally, breach and attack simulation tests can help identify weaknesses in SIEM and EDR rules, ensuring that threats are detected and mitigated promptly.


Source: Bleeping Computer — 2026-07-07