CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

UAT-7810 continues building ORB networks using new malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 516

As cited

Copy frozen at (site build).

threat intel

UAT-7810 continues building ORB networks using new malware

Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.

Why it matters: Organizations using Ruckus wireless routers and ASUS AiCloud devices should immediately verify patches for CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492, as unpatched devices are actively being compromised to serve as ORB infrastructure for subsequent attacks against high-value targets by secondary threat actors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

UAT-7810 continues building ORB networks using new malware

Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.

Why it matters: Organizations using Ruckus wireless routers and ASUS AiCloud devices should immediately verify patches for CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492, as unpatched devices are actively being compromised to serve as ORB infrastructure for subsequent attacks against high-value targets by secondary threat actors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary