The Containment Era is here. →Explore

Executive Summary

In July 2026, the Chinese state-sponsored threat actor UAT-7810 expanded its Operational Relay Box (ORB) network by deploying the LONGLEASH malware. This campaign targeted unpatched Ruckus and ASUS AiCloud routers, exploiting known vulnerabilities such as CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492. The ORB network serves as a relay infrastructure for other China-aligned APTs, facilitating covert cyber-espionage operations. The introduction of LONGLEASH, an evolution of the previously documented SHORTLEASH backdoor, enhances the ORB network's capabilities, including reverse shell access, multiple proxying methods, and the ability to act as an intermediate C2 server. This development underscores the persistent and evolving nature of state-sponsored cyber threats targeting critical infrastructure.

The emergence of LONGLEASH highlights a trend among nation-state actors to develop sophisticated malware that leverages existing vulnerabilities in widely used networking devices. This approach not only complicates attribution but also emphasizes the need for organizations to maintain rigorous patch management and network security practices to mitigate such threats.

Why This Matters Now

The deployment of LONGLEASH by UAT-7810 signifies an escalation in state-sponsored cyber-espionage activities, utilizing advanced malware to exploit known vulnerabilities in networking devices. This development underscores the urgent need for organizations to prioritize patch management and enhance network security measures to defend against evolving threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The ORB (Operational Relay Box) network is a covert infrastructure used by UAT-7810 to proxy their network traffic through compromised devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit vulnerabilities in unpatched routers would likely be constrained by enforcing strict access controls and continuous verification of device integrity.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges and establish persistence would likely be constrained by enforcing strict segmentation policies that limit access to critical systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely be constrained by enforcing east-west traffic controls that limit unauthorized inter-workload communication.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be constrained by providing comprehensive visibility and control over multicloud environments, detecting and disrupting unauthorized communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data would likely be constrained by enforcing strict egress policies that monitor and control outbound traffic.

Impact (Mitigations)

The attacker's ability to expand their network and conduct further malicious activities would likely be constrained by limiting the blast radius through strict segmentation and continuous monitoring.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • IT Security Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of network configurations and access credentials.

Recommended Actions

  • Implement regular patch management to address known vulnerabilities in networking devices.
  • Deploy Zero Trust Segmentation to limit lateral movement within the network.
  • Utilize East-West Traffic Security to monitor and control internal traffic flows.
  • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to malicious activities promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image