Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Continues building ORB networks using new malware

c7c9bfa9ffcd8fb6a2afe656f510c406ddc58ebff48ce1d0fd3fad951b46a36e

TLP:CLEAR
Active

SHA-256 Hash

Description

An advanced persistent threat actor designated UAT-7810 maintains and expands the LapDogs Operational Relay Box network infrastructure. This China-nexus group develops custom malware including SHORTLEASH and its evolved version LONGLEASH, alongside newly discovered tools DOGLEASH (a C-based backdoor), JARLEASH (a JAVA-based administrative backdoor), and LEASHTEST (a testing binary for MIPS devices). The actor exploits known vulnerabilities in unpatched Ruckus wireless routers and ASUS AiCloud devices, targeting networking equipment across multiple hardware platforms including MIPS, ARM, and x64. UAT-7810 establishes relay networks that secondary threat actors leverage for attacks against high-value targets. Infrastructure analysis reveals four command servers hosting malicious payloads, with one located in Hong Kong and others associated with VPS instances across multiple countries.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Continues building ORB networks using new malware
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of c7c9bfa9ffcd8fb6a2afe656f510c406ddc58ebff48ce1d0fd3fad951b46a36e

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.