Particle.news

China-Aligned Hackers Deploy LONGLEASH to Grow Router-Based Relay Network

Talos's July 7 report shows the upgraded toolkit lets the actor proxy many protocols through compromised Ruckus and ASUS routers to hide attack origins, enabling use by other APTs.

Overview

  • Cisco Talos reported on Tuesday that the actor tracked as UAT-7810 is replacing or extending its earlier SHORTLEASH implant with a more capable backdoor called LONGLEASH.
  • LONGLEASH adds reverse-shell access, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxying, SMTP client/server, TLS/PKI support, self-removal and the ability to act as an intermediate command server.
  • Talos also identified supporting tools—DOGLEASH (a Linux backdoor), JARLEASH (a Java admin tool) and LEASHTEST (an MIPS test utility)—used to broaden and test the relay network.
  • The campaign gains initial access by exploiting known, unpatched router flaws, including Ruckus CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 and ASUS AiCloud CVE-2025-2492, putting home and enterprise edge devices at risk.
  • Talos published indicators of compromise and urges defenders to patch internet-facing routers, harden device management, and hunt for the new IoCs because the ORB relays let other China-aligned APTs, such as UAT-5918, hide their origins.