LONGLEASH is a router- and embedded-device-focused backdoor associated with the China-nexus threat actor UAT-7810 and the LapDogs Operational Relay Box (ORB) network. It is an evolved successor to SHORTLEASH and appears designed to turn compromised edge infrastructure into durable relay and command infrastructure for downstream espionage operations. Reporting links UAT-7810 to building and maintaining ORB networks that can be used by secondary China-aligned actors, including UAT-5918, to obscure the origin of malicious traffic and support broader intrusion activity.
LONGLEASH has been observed on MIPS systems and is part of a broader multi-architecture toolset used against networking and edge devices. It retains earlier SHORTLEASH functions such as command-and-control communications, web server hosting, tunnel management, and operation as both a client and server, while adding substantial new networking and relay features. Documented capabilities include reverse shell access, proxying over HTTP, DNS, SOCKS, TCP, ICMP, and UDP, packet redirection, SMTP client and server functionality, TLS and PKI management, client authorization, and intermediate command forwarding between infected peers and upstream controllers. It can also remove itself when tampering or suspicious activity is detected, indicating an emphasis on defense evasion and operational resilience.
The malware is tied to campaigns that primarily exploit known vulnerabilities in unpatched Ruckus wireless routers, with related activity also linked to exploitation of ASUS AiCloud routers via CVE-2025-2492. Its role within the LapDogs ecosystem is consistent with infrastructure enablement rather than smash-and-grab intrusion objectives: compromised devices are repurposed as covert relay nodes, proxy points, and command intermediaries. This makes LONGLEASH a key component of a renewable espionage logistics layer built from compromised SOHO routers, IoT devices, and other edge systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
T1095 — Non-Application Layer Protocol (Command and Control)
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Backdoor for MIPS devices and IoT-style targets that provides reverse shell access, multiple proxying modes, packet forwarding, SMTP server/client functionality, TLS/PKI handling, and self-deletion when detection is suspected.
A newer backdoor derived from ShortLeash that supports command-and-control communication, web server hosting, tunnel management, and can act as both C&C and client. It can also function as an intermediate server, forwarding commands and data from the C&C to other peers.
An upgraded backdoor used in the LapDogs ORB ecosystem that adds proxying capabilities and can relay commands to other infected machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.