hacker-news · Crawled Jul 8, 2026

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

2 IoCs 1 Actors
Read original article ↗

AI Summary

China-linked threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by deploying updated malware variants such as LONGLEASH, DOGLEASH, and JARLEASH. The group targets internet-facing networking devices, including Ruckus and ASUS routers, leveraging known vulnerabilities to establish persistent access. These relay nodes are used to support secondary threat actors like UAT-5918 in conducting cyber attacks against high-value targets, particularly in critical infrastructure sectors. The continued development and testing of malware on MIPS-based platforms indicate ongoing refinement of their capabilities.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Package JARLEASH Details →
Filename LEASHTEST Details →

MITRE ATT&CK TTPs 6 techniques