hacker-news · Crawled Jul 8, 2026
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
2 IoCs 1 Actors
Read original article ↗
AI Summary
China-linked threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by deploying updated malware variants such as LONGLEASH, DOGLEASH, and JARLEASH. The group targets internet-facing networking devices, including Ruckus and ASUS routers, leveraging known vulnerabilities to establish persistent access. These relay nodes are used to support secondary threat actors like UAT-5918 in conducting cyber attacks against high-value targets, particularly in critical infrastructure sectors. The continued development and testing of malware on MIPS-based platforms indicate ongoing refinement of their capabilities.
AI-extracted · verify before operational use