Overview
- Cisco Talos reported on Tuesday that the actor tracked as UAT-7810 is replacing or extending its earlier SHORTLEASH implant with a more capable backdoor called LONGLEASH.
- LONGLEASH adds reverse-shell access, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxying, SMTP client/server, TLS/PKI support, self-removal and the ability to act as an intermediate command server.
- Talos also identified supporting tools—DOGLEASH (a Linux backdoor), JARLEASH (a Java admin tool) and LEASHTEST (an MIPS test utility)—used to broaden and test the relay network.
- The campaign gains initial access by exploiting known, unpatched router flaws, including Ruckus CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 and ASUS AiCloud CVE-2025-2492, putting home and enterprise edge devices at risk.
- Talos published indicators of compromise and urges defenders to patch internet-facing routers, harden device management, and hunt for the new IoCs because the ORB relays let other China-aligned APTs, such as UAT-5918, hide their origins.