UAT-7810 is a China-nexus advanced persistent threat actor focused on building, maintaining, and expanding Operational Relay Box (ORB) infrastructure rather than solely conducting end-target intrusions itself. The group is associated with the LapDogs ORB network, a relay mesh built from compromised internet-facing routers and other edge devices that can be used to proxy traffic, obscure operator origin, and support downstream espionage operations. Reporting has assessed with high confidence that UAT-7810 functions as an infrastructure and initial-access provider for other China-aligned actors, including UAT-5918, while remaining a distinct cluster despite some tooling overlap. The actor has shown a consistent preference for exploiting known but unpatched vulnerabilities in networking equipment, especially Ruckus wireless routers, and has also been linked to exploitation of ASUS AiCloud routers via CVE-2025-2492. Observed exploitation includes CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492. This tradecraft indicates a pragmatic emphasis on scalable access to poorly monitored edge infrastructure suitable for long-lived relay operations. UAT-7810 is known for a bespoke malware ecosystem centered on router and embedded-device operations across multiple architectures including MIPS, ARM, and x64. Malware associated with the actor includes SHORTLEASH and its more capable successor LONGLEASH, as well as DOGLEASH, JARLEASH, and LEASHTEST. LONGLEASH extends earlier SHORTLEASH functionality and supports reverse shell access, multi-protocol proxying, packet redirection, tunnel and connection management, TLS and PKI handling, SMTP functionality, client authorization, intermediate command-and-control forwarding, and self-removal when tampering is detected. DOGLEASH is a passive Linux backdoor capable of file operations, host reconnaissance, arbitrary shellcode execution, and in-memory code execution. JARLEASH is a Java-based administrative backdoor used on both compromised systems and actor-controlled infrastructure, providing web-based file management and file-transfer and remote-access services. LEASHTEST is a utility used to validate functionality on MIPS and IoT-class devices, reflecting active development and testing for embedded platforms. The group’s operational pattern suggests its primary mission is to convert compromised routers and edge devices into reusable logistics infrastructure for covert routing, tunneling, command-and-control relay, reconnaissance support, malware delivery, and potentially exfiltration support for affiliated China-aligned operations. Simplified Chinese comments observed in JARLEASH configuration further support the China nexus assessment. Known aliases in the provided reporting are limited to UAT-7810.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Maintains and expands the LapDogs ORB network, using compromised SOHO routers and edge devices as relay infrastructure for espionage logistics such as proxying, tunneling, traffic redirection, and intermediate C2 behavior.
China-nexus actor assessed with high confidence as responsible for building and proliferating ORB networks that can be used by secondary actors. The report documents its evolving malware arsenal and exploitation of internet-facing routers.
China-linked espionage actor operating an ORB network by compromising SOHO routers and expanding its toolkit with LongLeash, DogLeash, and JarLeash backdoors.
Operates and expands an Operational Relay Box network of hijacked edge devices and routers to provide relay infrastructure that masks the origin of cyber operations for other China-nexus espionage actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.