LEASHTEST is a small ELF utility associated with the China-nexus threat actor UAT-7810 and its LapDogs operational relay box infrastructure campaign. It is not considered malicious on its own; instead, it functions as a testing binary used to validate whether MIPS-based embedded and IoT devices can support behaviors needed by the actor’s broader malware ecosystem. Reported test functions include creating threads, spawning child processes, handling asynchronous timers, basic execution checks, and related runtime functionality on embedded Linux environments.
LEASHTEST appears to support UAT-7810’s development and deployment of router- and edge-device malware such as LONGLEASH, DOGLEASH, and JARLEASH. Its presence on a device is significant because it can indicate prior compromise or staging activity tied to efforts to expand ORB infrastructure built from compromised SOHO routers and other internet-facing embedded systems. The tooling around this cluster has been linked to exploitation of known vulnerabilities in networking devices, particularly unpatched Ruckus routers, and to multi-architecture operations spanning MIPS, ARM, and x64 platforms. LEASHTEST is best understood as a diagnostic or validation component within that ecosystem rather than as a standalone payload used for persistence, command execution, or data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers.
The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers.
The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers.
The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
ELF test utility, not inherently malicious, used to validate functionality on MIPS/IoT equipment in the actor's tooling ecosystem.
A non-malicious test binary used by UAT-7810 to validate functionality on MIPS platforms; notable as an indicator of compromise rather than malware used for intrusion effects.
An ELF binary used by UAT-7810 to test functionality on MIPS-based embedded devices, including thread creation, child process creation, and async timers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.