LONGLEASH malware: A fresh tool for an old threat
A Chinese advanced persistent threat group tracked as UAT-7810 has rolled out a new malware strain called LONGLEASH. The goal? To hijack internet-facing networking devices and expand a covert relay network. That’s according to new research from Cisco Talos, which has been tracking the group since mid-2025.
This isn’t a brand-new operation. UAT-7810 first surfaced publicly in June 2025 when researchers uncovered LapDogs, an Operational Relay Box (ORB) network the group had been quietly building. Now, with LONGLEASH, they’re refining their playbook.
What is an ORB network — and why should you care?
An Operational Relay Box network is exactly what it sounds like: a mesh of compromised devices used as relay points. Attackers route traffic through these boxes to hide their true location and activities. Think of it as a private VPN — but one built on someone else’s hardware, without their permission.
For an APT group like UAT-7810, an ORB network provides cover for espionage, data exfiltration, and launching follow-on attacks. The bigger the network, the harder it is to trace. That’s why LONGLEASH matters. It’s purpose-built to infect routers, switches, and other networking gear sitting on the public internet.
How LONGLEASH works: Targeting routers and switches
According to Cisco Talos, LONGLEASH is a bespoke backdoor — custom code, not off-the-shelf malware. It targets devices running Linux-based firmware, common in enterprise and small-office routers.
The infection chain typically starts with scanning for vulnerable services. Once inside, LONGLEASH establishes persistence, opens a reverse shell, and connects back to a command-and-control server. The malware then enrolls the device into the LapDogs ORB network.
Key capabilities include:
- Persistence mechanisms that survive reboots
- Encrypted communications to avoid detection
- Modular design allowing operators to push updates
- Device fingerprinting to identify high-value targets
The group isn’t just casting a wide net. Talos notes that UAT-7810 shows clear targeting preferences, focusing on devices from specific manufacturers — though researchers haven’t publicly named them yet.
UAT-7810 and the LapDogs connection
LapDogs first made headlines in June 2025. At the time, security researchers described it as a growing ORB network linked to Chinese state-sponsored activity. UAT-7810 was named as the operator.
Now, with LONGLEASH, the group is doubling down. The new malware suggests UAT-7810 has development resources and is actively iterating. That’s a bad sign for defenders. It means the group is learning from past failures and hardening its tools.
Cisco Talos believes the LapDogs network already spans hundreds of compromised devices, mostly in Asia and North America. The addition of LONGLEASH could accelerate that growth.
What this means for network defenders
Here’s the practical takeaway: if you manage internet-facing networking gear — especially older routers or switches — you’re a potential target. UAT-7810 scans for known vulnerabilities and weak credentials.
Steps to reduce risk:
- Patch aggressively. Many exploited flaws have patches available. Apply them.
- Change default credentials. This is still the top entry vector for groups like UAT-7810.
- Disable remote management if you don’t absolutely need it.
- Monitor for unusual outbound connections from network devices, especially on non-standard ports.
The LONGLEASH malware isn’t a mass-market threat — yet. But for organizations targeted by Chinese APT groups, it’s a clear escalation. Cisco Talos has published indicators of compromise (IOCs) for LONGLEASH, including hashes and C2 domains. Defenders should pull those into their threat intelligence feeds immediately.
The bigger picture: ORB networks as a persistent threat
ORB networks aren’t new. Russian and Iranian groups have used similar tactics for years. But the Chinese-linked activity around LapDogs and LONGLEASH highlights how ORBs are becoming standard infrastructure for state-sponsored espionage.
What’s different here is the custom malware. Most ORB networks rely on commodity tools like SSH tunnels or SOCKS proxies. LONGLEASH is purpose-built, suggesting UAT-7810 has long-term ambitions.
As one researcher put it: “They’re not just borrowing devices. They’re building an army of relays.”
Expect more variants to appear. And expect the LapDogs network to keep growing — unless defenders start treating every internet-connected router as a potential battlefield.