JARLEASH is a Java-based backdoor associated with the China-nexus threat actor UAT-7810 and the expansion of the LapDogs Operational Relay Box (ORB) network. It has been deployed both on attacker-controlled infrastructure and on compromised systems where a Java runtime is available, serving primarily as an administrative access tool rather than a router-resident implant. Its observed functionality includes a web-based file management interface and server components for FTP, SFTP, and Netcat, giving operators convenient remote administration and file transfer capabilities on systems under their control. Reporting also notes Simplified Chinese comments in its configuration, consistent with broader attribution of the activity cluster to Chinese-speaking operators. JARLEASH forms part of a wider custom malware ecosystem that includes LONGLEASH, DOGLEASH, and LEASHTEST, used by UAT-7810 to build and maintain relay infrastructure from compromised edge devices and supporting servers. The broader campaign has focused on exploiting known vulnerabilities in internet-facing networking equipment, especially unpatched Ruckus routers, to sustain ORB infrastructure that can support downstream espionage operations by associated China-aligned actors such as UAT-5918.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
The backdoor can host a web-based file management interface and FTP and SFTP servers, and can run a netcat server on a provided IP and port number.
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Java JAR backdoor deployed on attacker infrastructure and compromised systems, offering web-based file management plus FTP/SFTP and Netcat-style server capabilities.
A Java-based backdoor used to access compromised systems. It is deployed with a script that kills other instances before spawning a Java container, and it can host a web-based file management interface, FTP and SFTP servers, and run a netcat server.
A Java-based backdoor or management tool used to manage the group's servers in support of the LapDogs ORB network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.