ShortLeash is a custom backdoor associated with the LapDogs operational relay box network, a China-nexus espionage infrastructure campaign focused on compromising small office/home office and edge networking devices. It has been used to maintain stealthy, long-term access on infected systems and to incorporate those devices into relay infrastructure that can proxy or obscure downstream malicious activity. Reporting links the broader activity to UAT-7810, with evidence that the resulting infrastructure has supported secondary China-aligned actors including UAT-5918.
ShortLeash has been observed primarily on Linux-based SOHO and embedded devices, especially routers and wireless access points, with a notable concentration on Ruckus and Buffalo equipment. It has also been associated with artifacts suggesting a Windows variant exists, but Linux support is the clearest high-confidence platform. The malware is typically deployed after exploitation of known vulnerabilities in exposed, unpatched devices. Documented intrusion activity against the broader campaign includes exploitation of multiple router vulnerabilities, particularly in Ruckus devices, and use against ASUS AiCloud routers in related expansion efforts.
Functionally, ShortLeash is a persistence-oriented backdoor that can contact external command infrastructure, host a web server on the compromised device, manage tunnels, and operate as both a command-and-control server and client. It has been described as providing root-level access on infected devices. For persistence, it has been observed installing itself as a service so it survives reboot. Operationally, it can masquerade as a legitimate web service by setting up a fake Nginx server and generating self-signed TLS certificates with spoofed LAPD-themed metadata, a distinctive trait used to track LapDogs infections. This design supports covert, durable access while allowing compromised devices to continue functioning as relay nodes.
ShortLeash is part of an evolving malware lineage. Cisco Talos identified LONGLEASH as a newer version built from the same codebase and intended to replace or extend ShortLeash with substantially broader proxying, relay, and remote access capabilities. The continued development of this malware family, alongside related tools such as DOGLEASH, JARLEASH, and LEASHTEST, indicates an active effort to expand and maintain ORB infrastructure for espionage support operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
Campaigns observed earlier this year have also singled out ASUS AiCloud Routers susceptible to CVE-2025-2492, indicating potential attempts to broaden the ORB network.
"...infecting small office/home office (SOHO) routers with a custom backdoor named ShortLeash, which provides stealthy, long-term access to the compromised devices." | Most of the infected devices are Ruckus Wireless access points, followed by Buffalo Technology AirStation wireless routers. Running old and unpatched SSH services, they were found vulnerable to CVE-2015-1548 and CVE-2017-17663.
"The attacks themselves weaponize N-day security vulnerabilities (e.g., CVE-2015-1548 and CVE-2017-17663) to obtain initial access." | LapDogs' beating heart is a custom backdoor called ShortLeash that's engineered to enlist infected devices in the network.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LONGLEASH : Nouvelle version de SHORTLEASH, nommée en interne “ff-agent” et “nz1.0”.
LapDogs leverages a custom backdoor ("ShortLeash") with unique self-signed TLS certificates mimicking LAPD metadata, focusing on Linux-based SOHO devices (notably Ruckus and Buffalo routers).
LapDogs leverages a custom backdoor ("ShortLeash") with unique self-signed TLS certificates mimicking LAPD metadata, focusing on Linux-based SOHO devices (notably Ruckus and Buffalo routers).
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The recently identified LongLeash backdoor builds on the functionality previously observed in ShortLeash, such as command-and-control (C&C) communication
This type of infrastructure ... allows threat actors to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier backdoor variant referenced as the predecessor to LONGLEASH.
An earlier backdoor used to infect SOHO routers in the LapDogs espionage infrastructure campaign. LongLeash builds on functionality previously observed in ShortLeash.
Custom malware used by UAT-7810 as part of its ORB operations. It includes a backdoor capable of contacting an external server, hosting a web server, and acting as both a command-and-control server and client.
A custom backdoor used by UAT-7810 on compromised devices, apparently an earlier version being superseded by LONGLEASH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.