The Containment Era is here. →Explore

Executive Summary

In July 2026, the Chinese advanced persistent threat (APT) group UAT-7810 enhanced its Operational Relay Box (ORB) network by deploying new malware variants, notably LONGLEASH, DOGLEASH, and JARLEASH. These tools target unpatched Ruckus wireless routers, exploiting vulnerabilities such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, to establish a robust infrastructure for subsequent cyber operations. The ORB network serves as a relay platform, facilitating attacks by other China-aligned threat actors, including UAT-5918, which has been implicated in cyber attacks against critical infrastructure in Taiwan since at least 2023. The development of these sophisticated malware tools underscores the evolving capabilities of UAT-7810 and the persistent threat posed to global network security. Organizations utilizing vulnerable networking devices are at heightened risk, emphasizing the need for proactive defense measures and timely patch management to mitigate potential intrusions.

Why This Matters Now

The rapid evolution of UAT-7810's malware arsenal highlights the increasing sophistication of state-sponsored cyber threats. Organizations must prioritize securing internet-facing devices and stay vigilant against emerging attack vectors to protect critical infrastructure and sensitive data.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

UAT-7810 exploits known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, to compromise devices and expand their ORB network.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit vulnerabilities, move laterally, and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit unpatched vulnerabilities in network devices would likely be constrained, reducing the risk of initial compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges and establish persistence would likely be constrained, limiting their control over compromised devices.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the scope of compromised devices.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be constrained, limiting their communication with compromised devices.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The attacker's ability to expand their network and target high-value assets would likely be constrained, reducing the overall impact of the attack.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • IT Security Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of network configurations and administrative credentials.

Recommended Actions

  • Implement East-West Traffic Security to monitor and control lateral movement within the network.
  • Deploy Zero Trust Segmentation to enforce least privilege access and limit the spread of malware.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
  • Apply Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Regularly update and patch networking devices to mitigate known vulnerabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image