Executive Summary
In July 2026, the Chinese advanced persistent threat (APT) group UAT-7810 enhanced its Operational Relay Box (ORB) network by deploying new malware variants, notably LONGLEASH, DOGLEASH, and JARLEASH. These tools target unpatched Ruckus wireless routers, exploiting vulnerabilities such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, to establish a robust infrastructure for subsequent cyber operations. The ORB network serves as a relay platform, facilitating attacks by other China-aligned threat actors, including UAT-5918, which has been implicated in cyber attacks against critical infrastructure in Taiwan since at least 2023. The development of these sophisticated malware tools underscores the evolving capabilities of UAT-7810 and the persistent threat posed to global network security. Organizations utilizing vulnerable networking devices are at heightened risk, emphasizing the need for proactive defense measures and timely patch management to mitigate potential intrusions.
Why This Matters Now
The rapid evolution of UAT-7810's malware arsenal highlights the increasing sophistication of state-sponsored cyber threats. Organizations must prioritize securing internet-facing devices and stay vigilant against emerging attack vectors to protect critical infrastructure and sensitive data.
Attack Path Analysis
UAT-7810 exploited known vulnerabilities in unpatched Ruckus wireless routers to gain initial access. They deployed custom malware to establish persistence and escalate privileges. The attackers moved laterally to compromise additional devices within the network. They set up command and control channels using the compromised devices as relay points. Data was exfiltrated through the established ORB network. The impact included the expansion of the ORB network, enabling further malicious activities.
Kill Chain Progression
Initial Compromise
Description
UAT-7810 exploited known vulnerabilities in unpatched Ruckus wireless routers, such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, to gain initial access to the network.
Related CVEs
CVE-2020-22653
CVSS 9.8An authentication bypass vulnerability in Ruckus Wireless Admin allows unauthenticated remote attackers to gain administrative access.
Affected Products:
Ruckus Wireless Admin – < 10.4
Exploit Status:
exploited in the wildCVE-2020-22658
CVSS 9.8An unauthorized boot image switch vulnerability in Ruckus Wireless Devices allows remote attackers to execute arbitrary code.
Affected Products:
Ruckus Wireless Devices – < 10.4
Exploit Status:
exploited in the wildCVE-2023-25717
CVSS 9.8An image signature injection vulnerability in Ruckus Wireless Products allows remote attackers to execute arbitrary code.
Affected Products:
Ruckus Wireless Products – < 10.4
Exploit Status:
exploited in the wildCVE-2025-2492
CVSS 9.2An authentication bypass vulnerability in ASUS AiCloud Routers allows unauthenticated remote attackers to gain administrative access.
Affected Products:
ASUS AiCloud Routers – < 3.0.0.4.386
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Hijack Execution Flow
Remote Services
Ingress Tool Transfer
Remote Access Software
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical infrastructure exposure to UAT-7810's internet-facing device compromises threatens network integrity, requiring enhanced east-west traffic security and zero trust segmentation.
Computer Networking
Direct targeting of networking devices by Chinese APT exploiting ORB networks demands immediate egress security enforcement and multicloud visibility controls.
Financial Services
APT lateral movement through compromised networking infrastructure poses data exfiltration risks, necessitating encrypted traffic protection and anomaly detection capabilities.
Government Administration
State-sponsored threat actor's advanced persistent techniques against critical infrastructure require comprehensive threat detection and secure hybrid connectivity implementation.
Sources
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malwarehttps://thehackernews.com/2026/07/china-linked-uat-7810-expands-orb.htmlVerified
- Chinese hackers develop LONGLEASH malware to expand ORB networkhttps://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/Verified
- China-Linked APT Expands Arsenal With New 'Leash' Backdoorshttps://www.securityweek.com/china-linked-apt-expands-arsenal-with-new-leash-backdoors/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit vulnerabilities, move laterally, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit unpatched vulnerabilities in network devices would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and establish persistence would likely be constrained, limiting their control over compromised devices.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the scope of compromised devices.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, limiting their communication with compromised devices.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.
The attacker's ability to expand their network and target high-value assets would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Network Operations
- IT Security Management
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of network configurations and administrative credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement East-West Traffic Security to monitor and control lateral movement within the network.
- • Deploy Zero Trust Segmentation to enforce least privilege access and limit the spread of malware.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Regularly update and patch networking devices to mitigate known vulnerabilities.



