LapDogs & Leashes: Cisco Talos tracking UAT-7810's proliferation of their ORB Network

Last Updated: 2026-07-07T22:33:53Z

What’s Happening

Cisco Talos is tracking an APT “UAT-7810” (China-nexus) that is actively exploiting ASUS (AiCloud enabled) and Ruckus routers to proliferate their LapDogs Operational Relay Box (ORB) network using new malware.

You can think of an ORB network like a botnet of compromised devices, but for proxying traffic rather than for DDoSing or spamming

They are primarily exploiting the following vulnerabilities in Ruckus wireless routers:

As well as CVE-2025-2492 in ASUS routers with “AiCloud” functionality.

Additionally, they are expanding their malware loadout from the previously disclosed “SHORTLEASH” to:

  • a more fully featured version of SHORTLEASH dubbed “LONGLEASH”
  • a Java-based HTTP file management and S/FTP server with netcat capability dubbed “JARLEASH”
  • a simple C-based backdoor dubbed “DOGLEASH”
  • an IOT functionality testing ELF binary compiled for MIPS dubbed “LEASHTEST”

Actions


Make sure you’re either patched against the above CVEs, or upgrade EoL hardware. Review logs on these devices for suspicious activity (may be able to trigger the disconnect functionality of LONGLEASH), and as always review the IoCs for presence.

IoCs


All IoCs are at the bottom of the linked blog post, but the infrastructure serving the malware is:

Value Type
194.233.92[.]26 IPv4 address
217.15.160[.]247 IPv4 address
217.15.164[.]147 IPv4 address
95.182.100[.]231 IPv4 address
http[:]//217[.]15.160[.]247:8088/ URL
http[:]//217[.]15.160[.]247:2222/ URL
http[:]//217[.]15.160[.]247:99/ URL
http[:]//194[.]233.92[.]26:8088/ URL
http[:]//194[.]233.92[.]26:2222/ URL
http[:]//217[.]15.164[.]147:99/ URL
http[:]//217[.]15.164[.]147:8088/ URL
http[:]//217[.]15.164[.]147:2222/ URL
http[:]//95[.]182.100[.]231:2222/ URL

Additional sources


2 Likes