1mo ago · hacker-news
China-linked threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by deploying updated malware variants such as LONGLEASH, DOGLEASH, and JARLEASH. The group targets internet-facing networking devices, including Ruckus and ASUS routers, leveraging known vulnerabilities to establish persistent access. These relay nodes are used to support secondary threat actors like UAT-5918 in conducting cyber attacks against high-value targets, particularly in critical infrastructure sectors. The continued development and testing of malware on MIPS-based platforms indicate ongoing refinement of their capabilities.