Last Updated: 2026-07-07T22:33:53Z
What’s Happening
Cisco Talos is tracking an APT “UAT-7810” (China-nexus) that is actively exploiting ASUS (AiCloud enabled) and Ruckus routers to proliferate their LapDogs Operational Relay Box (ORB) network using new malware.
You can think of an ORB network like a botnet of compromised devices, but for proxying traffic rather than for DDoSing or spamming
They are primarily exploiting the following vulnerabilities in Ruckus wireless routers:
As well as CVE-2025-2492 in ASUS routers with “AiCloud” functionality.
Additionally, they are expanding their malware loadout from the previously disclosed “SHORTLEASH” to:
- a more fully featured version of SHORTLEASH dubbed “LONGLEASH”
- a Java-based HTTP file management and S/FTP server with netcat capability dubbed “JARLEASH”
- a simple C-based backdoor dubbed “DOGLEASH”
- an IOT functionality testing ELF binary compiled for MIPS dubbed “LEASHTEST”
Actions
Make sure you’re either patched against the above CVEs, or upgrade EoL hardware. Review logs on these devices for suspicious activity (may be able to trigger the disconnect functionality of LONGLEASH), and as always review the IoCs for presence.
IoCs
All IoCs are at the bottom of the linked blog post, but the infrastructure serving the malware is:
| Value | Type |
|---|---|
| 194.233.92[.]26 | IPv4 address |
| 217.15.160[.]247 | IPv4 address |
| 217.15.164[.]147 | IPv4 address |
| 95.182.100[.]231 | IPv4 address |
| http[:]//217[.]15.160[.]247:8088/ | URL |
| http[:]//217[.]15.160[.]247:2222/ | URL |
| http[:]//217[.]15.160[.]247:99/ | URL |
| http[:]//194[.]233.92[.]26:8088/ | URL |
| http[:]//194[.]233.92[.]26:2222/ | URL |
| http[:]//217[.]15.164[.]147:99/ | URL |
| http[:]//217[.]15.164[.]147:8088/ | URL |
| http[:]//217[.]15.164[.]147:2222/ | URL |
| http[:]//95[.]182.100[.]231:2222/ | URL |