bleeping-computer · Crawled Jul 7, 2026

Chinese hackers develop LONGLEASH malware to expand ORB network

Read original article ↗

AI Summary

Chinese threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by deploying updated and new malware variants, including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. These tools are used to compromise internet-facing networking devices, primarily unpatched Ruckus and ASUS routers, leveraging known vulnerabilities. The ORB infrastructure enables other China-aligned APTs to proxy traffic through compromised regional devices to evade detection and hinder attribution.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.