DOGLEASH is a lightweight Linux backdoor associated with the China-nexus threat actor UAT-7810 and the LapDogs Operational Relay Box (ORB) infrastructure campaign. It is written in C and has been used as part of a broader router- and edge-device-focused malware ecosystem that also includes LONGLEASH, JARLEASH, and LEASHTEST. UAT-7810 is assessed to use this tooling to build and maintain relay infrastructure that can support downstream espionage operations by China-aligned actors, including infrastructure support for UAT-5918.
DOGLEASH is deployed on compromised Linux devices, including networking and embedded systems, via shell scripts following exploitation of known vulnerabilities in internet-facing edge equipment, particularly unpatched Ruckus routers. Deployment scripts have been observed modifying local firewall rules to permit inbound TCP traffic to the port on which the implant listens. The malware operates as a passive backdoor, binding to a hardcoded TCP port and waiting for authenticated inbound commands.
Its supported functionality includes execution of arbitrary shellcode or code in memory, shell command execution, file reading, file renaming, listener shutdown, and collection of operating system information. These capabilities make it suitable for post-compromise access, lightweight remote administration, and follow-on payload execution on compromised Linux infrastructure. Variants have been hosted for multiple CPU architectures, including MIPS, ARM, and x64, reflecting its role in compromising heterogeneous router and embedded-device environments used as ORB nodes.
DOGLEASH is best understood as a post-exploitation access tool within UAT-7810’s infrastructure-building operations rather than a mass-market crimeware family. Its quiet listening behavior, small feature set, and multi-architecture deployment align with the operational goal of maintaining durable access to compromised relay devices that can be incorporated into covert proxy and command infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Passive Linux backdoor written in C that listens on a hardcoded TCP port and can execute arbitrary shellcode, read and rename files, and collect operating system information.
A C-based passive backdoor deployed by shell script. It can execute commands, read and rename files, close its socket listener, retrieve OS information, and execute code in memory.
A previously unknown backdoor that executes commands on compromised Linux devices within the actor's hijacked-device network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.