Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors uat-7810

Also known as: tracked as, JARLEASH, LEASHTEST, NosyDoor

Description

UAT‑7810 is a sophisticated threat actor with a primary motivation of financial gain yet demonstrates APT‑level persistence and reach. It builds and maintains an Operational Relay Box (ORB) network that serves as a backbone for both its own operations and for other China‑aligned groups, enabling multi‑hop traffic relays via reverse shells, proxy tunneling, and internal/external proxies. The actor’s toolset includes custom backdoors—LONGLEASH, SHORTLEASH, DOGLEASH, JARLEASH, and the MIPS testing binary LEASHTEST—as well as other malware families such as NetDraft/NosyDoor, CloudSorcerer, SNAPPYBEE/DeedRAT, ZingDoor, and Draculoader. These binaries are deployed on a wide array of hardware platforms (MIPS, ARM, x64) and often delivered via shell scripts that download and execute payloads through FTP/SFTP or Netcat. Initial access is routinely achieved by exploiting unpatched Ruckus wireless routers using CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717, and the newer CVE‑2025‑2492. Once inside, the actor leverages these devices as pivot points, extending its ORB network and offering intermediary C&C capabilities to other actors. The infrastructure is distributed across multiple command servers, including a Hong Kong‑based host and several VPS instances worldwide. UAT‑7810’s operations are indicative of a multi-phase attack model that begins with device exploitation, extends through lateral movement via compromised IoT hardware, introduces custom backdoors for persistent footholds, and ultimately channels traffic through its ORB relay infrastructure to support broader threat actor objectives.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Manufacturing
Oil gas
Retail
Construction
Telecommunications

Targeted Countries / Regions

CN
AE
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

UAT‑7810 is a China‑aligned advanced persistent threat that has expanded its Operational Relay Box (ORB) network and developed a family of cross‑platform backdoors. The group actively exploits known vulnerabilities in unpatched Ruckus wireless routers to gain initial access, then deploys custom malware such as LONGLEASH and DOGLEASH across MIPS, ARM, and x64 devices to facilitate lateral movement and provide intermediary command‑and‑control for other actors. Its operations target government, critical infrastructure, industrial, and commercial sectors in China, the UAE, Japan, and beyond.

Goals & Targeting

The strategic objective of UAT‑7810 appears two‑fold: first, to establish a resilient, distributed network of compromised networking equipment that can serve as an intermediary C&C hub; second, to leverage this infrastructure for financial exploitation against high‑value targets across multiple sectors. The actor deliberately selects devices that are widely deployed yet often unpatched—particularly Ruckus wireless routers—to maximize the reach and longevity of its foothold while remaining covert. By supporting secondary threat actors through the ORB network, UAT‑7810 increases the overall effectiveness and scale of campaigns with minimal operational risk. Its targeting profile focuses on government entities, critical infrastructure such as power and telecommunications, manufacturing facilities, oil and gas platforms, retail chains, construction enterprises, and related support services. These sectors provide both high potential financial returns (e.g., ransomware or data theft) and strategic influence. The geographic focus spans primarily the People's Republic of China, the United Arab Emirates, and Japan—regions where governmental and industrial networks are often interconnected with legacy Ruckus and ASUS AiCloud devices. Overall UAT‑7810 pursues missions that enhance its command‑control capabilities while injecting monetary value via ransomware, data exfiltration, or strategic sabotage.

Enhanced Description

Key Capabilities

  • Build and maintain Operational Relay Box (ORB) networks
  • Develop custom backdoors: LONGLEASH, SHORTLEASH, DOGLEASH, JARLEASH, LEASHTEST
  • Deploy malware across MIPS, ARM, and x64 platforms
  • Exploit unpatched Ruckus wireless routers using CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717, CVE‑2025‑2492
  • Use shell scripts to download and execute payloads
  • Transfer files via FTP/SFTP/Netcat
  • Test functionality on MIPS devices with LEASHTEST
  • Host custom malware: NetDraft/NosyDoor, CloudSorcerer, SNAPPYBEE/DeedRAT, ZingDoor, Draculoader
  • Employ reverse shells and multi‑hop proxies to relay traffic through ORBs
  • Serve as intermediate C&C server for secondary threat actors

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Command and Control

ATT&CK Techniques

T1584.008
T1071.004
T1071
T1190
T1572
T1071.003
T1505.003
T1071.002
T1090.003
T1071.001
T1090.001
T1053.003
T1105
T1055

Software / Tooling

LONGLEASH
SHORTLEASH
DOGLEASH
JARLEASH
LEASHTEST

Campaigns & Victims

UAT‑7810 has demonstrated a consistent pattern of expanding its ORB network on a recurring schedule. The actor launches new backdoor variants—most recently LONGLEASH and DOGLEASH—while simultaneously exploiting publicly disclosed router vulnerabilities to broaden its foothold across diverse hardware ecosystems. Operational tempo appears moderate, with infrastructure updates (new C&C IPs, additional malware uploads) observed roughly every few weeks. Victims tend to be in sectors where network devices are ubiquitous yet under‑managed: government agencies, critical utilities, and large industrial sites. The attacker’s multi‑tiered approach (device exploitation → backdoor insertion → traffic relaying) allows for persistent access while masking their presence. Notable past operations include the compromise of multiple Ruckus Air‑Max routers in Asia-Pacific installations, followed by the injection of a custom backdoor that acted as a pivot to more valuable corporate targets. Recent indicators also suggest that UAT‑7810 has begun embedding its ORB infrastructure within supply‑chain environments, potentially extending its reach beyond direct device exploitation.

IOC Patterns

  • CVE identifier
  • IP address (IPv4)
  • SHA-256 hash
  • File name
  • Domain name

Recommended Actions

  • Patch all network devices to remediate CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 before exploitation occurs.
  • Block IP addresses identified as malicious payload hosts such as 217.15.164.147 and 95.182.100.231 at perimeter firewalls or DNS sinkholes.
  • Implement active monitoring of startup scripts and suspicious binaries (e.g., DOGLEASH, JARLEASH) on all endpoints using baselines and behavior analytics.
  • Segment corporate networks to isolate critical infrastructure from consumer‑grade device segments, limiting lateral movement via the ORB network.
  • Deploy intrusion detection and prevention systems with signatures for known backdoor binaries and C&C traffic patterns, including multi‑hop proxy activity.
  • Regularly audit firmware versions on Ruckus wireless routers and ASUS AiCloud devices, ensuring timely updates;
  • Enforce strict firewall rules to block unauthorized outbound application layer protocols (e.g., DNS tunneling, SMTP exfiltration) often used by these actors.
  • Educate security teams on Indicators of Compromise specific to UAT‑7810’s toolset, such as LEASHTEST execution on MIPS devices.

Suggested Tags

APT
China‑nexus
Operational Relay Box (ORB) Network
Wireless Router Exploitation
MIPS IoT Devices
Custom Backdoor Development
Multi-hop Proxying
Intermediate Command-and-Control
Network Device Targeting

Confidence Assessment

The data pool contains multiple corroborating sources indicating that UAT‑7810 is an established APT with a defined toolset and clear operational patterns. Confidence in the identification of its exploitation techniques (router CVEs) and custom backdoors is high due to repeated sightings across different analyst reports. However, gaps remain regarding the breadth of secondary threat actors supported by the ORB network, precise geographic footprint of all command servers, and the full extent of the actor’s persistence mechanisms on victim networks. Continuous telemetry and IOC harvesting are recommended to close these knowledge gaps.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: NosyDoor
  2. aviatrix.ai — Cited by web research for: T1190
  3. phishtankdigital.com — Cited by web research for: Qilin
  4. blog.talosintelligence.com — Cited by web research for: Unknown

Intel Summary

14

Techniques

43

Tools

0

Campaigns

38

IOCs

0

Observed Data

6

Tactics

Tags

APT
Backdoor / C2
China‑nexus
Operational Relay Box (ORB) Network
Wireless Router Exploitation
MIPS IoT Devices
Custom Backdoor Development
Multi-hop Proxying
Intermediate Command-and-Control
Network Device Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.