Also known as: tracked as, JARLEASH, LEASHTEST, NosyDoor
UAT‑7810 is a sophisticated threat actor with a primary motivation of financial gain yet demonstrates APT‑level persistence and reach. It builds and maintains an Operational Relay Box (ORB) network that serves as a backbone for both its own operations and for other China‑aligned groups, enabling multi‑hop traffic relays via reverse shells, proxy tunneling, and internal/external proxies. The actor’s toolset includes custom backdoors—LONGLEASH, SHORTLEASH, DOGLEASH, JARLEASH, and the MIPS testing binary LEASHTEST—as well as other malware families such as NetDraft/NosyDoor, CloudSorcerer, SNAPPYBEE/DeedRAT, ZingDoor, and Draculoader. These binaries are deployed on a wide array of hardware platforms (MIPS, ARM, x64) and often delivered via shell scripts that download and execute payloads through FTP/SFTP or Netcat. Initial access is routinely achieved by exploiting unpatched Ruckus wireless routers using CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717, and the newer CVE‑2025‑2492. Once inside, the actor leverages these devices as pivot points, extending its ORB network and offering intermediary C&C capabilities to other actors. The infrastructure is distributed across multiple command servers, including a Hong Kong‑based host and several VPS instances worldwide. UAT‑7810’s operations are indicative of a multi-phase attack model that begins with device exploitation, extends through lateral movement via compromised IoT hardware, introduces custom backdoors for persistent footholds, and ultimately channels traffic through its ORB relay infrastructure to support broader threat actor objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑7810 is a China‑aligned advanced persistent threat that has expanded its Operational Relay Box (ORB) network and developed a family of cross‑platform backdoors. The group actively exploits known vulnerabilities in unpatched Ruckus wireless routers to gain initial access, then deploys custom malware such as LONGLEASH and DOGLEASH across MIPS, ARM, and x64 devices to facilitate lateral movement and provide intermediary command‑and‑control for other actors. Its operations target government, critical infrastructure, industrial, and commercial sectors in China, the UAE, Japan, and beyond.
Goals & Targeting
The strategic objective of UAT‑7810 appears two‑fold: first, to establish a resilient, distributed network of compromised networking equipment that can serve as an intermediary C&C hub; second, to leverage this infrastructure for financial exploitation against high‑value targets across multiple sectors. The actor deliberately selects devices that are widely deployed yet often unpatched—particularly Ruckus wireless routers—to maximize the reach and longevity of its foothold while remaining covert. By supporting secondary threat actors through the ORB network, UAT‑7810 increases the overall effectiveness and scale of campaigns with minimal operational risk. Its targeting profile focuses on government entities, critical infrastructure such as power and telecommunications, manufacturing facilities, oil and gas platforms, retail chains, construction enterprises, and related support services. These sectors provide both high potential financial returns (e.g., ransomware or data theft) and strategic influence. The geographic focus spans primarily the People's Republic of China, the United Arab Emirates, and Japan—regions where governmental and industrial networks are often interconnected with legacy Ruckus and ASUS AiCloud devices. Overall UAT‑7810 pursues missions that enhance its command‑control capabilities while injecting monetary value via ransomware, data exfiltration, or strategic sabotage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT‑7810 has demonstrated a consistent pattern of expanding its ORB network on a recurring schedule. The actor launches new backdoor variants—most recently LONGLEASH and DOGLEASH—while simultaneously exploiting publicly disclosed router vulnerabilities to broaden its foothold across diverse hardware ecosystems. Operational tempo appears moderate, with infrastructure updates (new C&C IPs, additional malware uploads) observed roughly every few weeks. Victims tend to be in sectors where network devices are ubiquitous yet under‑managed: government agencies, critical utilities, and large industrial sites. The attacker’s multi‑tiered approach (device exploitation → backdoor insertion → traffic relaying) allows for persistent access while masking their presence. Notable past operations include the compromise of multiple Ruckus Air‑Max routers in Asia-Pacific installations, followed by the injection of a custom backdoor that acted as a pivot to more valuable corporate targets. Recent indicators also suggest that UAT‑7810 has begun embedding its ORB infrastructure within supply‑chain environments, potentially extending its reach beyond direct device exploitation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data pool contains multiple corroborating sources indicating that UAT‑7810 is an established APT with a defined toolset and clear operational patterns. Confidence in the identification of its exploitation techniques (router CVEs) and custom backdoors is high due to repeated sightings across different analyst reports. However, gaps remain regarding the breadth of secondary threat actors supported by the ORB network, precise geographic footprint of all command servers, and the full extent of the actor’s persistence mechanisms on victim networks. Continuous telemetry and IOC harvesting are recommended to close these knowledge gaps.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
43
Tools
0
Campaigns
38
IOCs
0
Observed Data
6
Tactics