Executive Summary
In July 2026, the Chinese state-sponsored threat actor UAT-7810 expanded its Operational Relay Box (ORB) network by deploying the LONGLEASH malware. This campaign targeted unpatched Ruckus and ASUS AiCloud routers, exploiting known vulnerabilities such as CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492. The ORB network serves as a relay infrastructure for other China-aligned APTs, facilitating covert cyber-espionage operations. The introduction of LONGLEASH, an evolution of the previously documented SHORTLEASH backdoor, enhances the ORB network's capabilities, including reverse shell access, multiple proxying methods, and the ability to act as an intermediate C2 server. This development underscores the persistent and evolving nature of state-sponsored cyber threats targeting critical infrastructure.
The emergence of LONGLEASH highlights a trend among nation-state actors to develop sophisticated malware that leverages existing vulnerabilities in widely used networking devices. This approach not only complicates attribution but also emphasizes the need for organizations to maintain rigorous patch management and network security practices to mitigate such threats.
Why This Matters Now
The deployment of LONGLEASH by UAT-7810 signifies an escalation in state-sponsored cyber-espionage activities, utilizing advanced malware to exploit known vulnerabilities in networking devices. This development underscores the urgent need for organizations to prioritize patch management and enhance network security measures to defend against evolving threats.
Attack Path Analysis
UAT-7810 exploited known vulnerabilities in unpatched Ruckus and ASUS AiCloud routers to gain initial access. They deployed malware such as LONGLEASH and DOGLEASH to establish persistence and escalate privileges. The attackers moved laterally by compromising additional devices within the network. They set up command and control channels using the compromised devices as relay nodes. Data exfiltration was conducted through these established channels. The impact included the expansion of the ORB network, enabling further malicious activities.
Kill Chain Progression
Initial Compromise
Description
UAT-7810 exploited known vulnerabilities in unpatched Ruckus and ASUS AiCloud routers to gain initial access.
Related CVEs
CVE-2020-22653
CVSS 9.8A vulnerability in Ruckus Wireless devices allows attackers to exploit the official image signature to force injection of unauthorized image signatures.
Affected Products:
Ruckus Wireless R310 Firmware – 10.5.1.0.199
Ruckus Wireless R500 Firmware – 10.5.1.0.199
Ruckus Wireless R600 Firmware – 10.5.1.0.199
Ruckus Wireless T300 Firmware – 10.5.1.0.199
Ruckus Wireless T301n Firmware – 10.5.1.0.199
Ruckus Wireless T301s Firmware – 10.5.1.0.199
Ruckus Wireless SmartCell Gateway 200 (SCG200) Firmware – < 3.6.2.0.795
Ruckus Wireless SmartZone 100 (SZ-100) Firmware – < 3.6.2.0.795
Ruckus Wireless SmartZone 300 (SZ300) Firmware – < 3.6.2.0.795
Ruckus Wireless Virtual SmartZone (vSZ) Firmware – < 3.6.2.0.795
Ruckus Wireless ZoneDirector 1100 Firmware – 9.10.2.0.130
Ruckus Wireless ZoneDirector 1200 Firmware – 10.2.1.0.218
Ruckus Wireless ZoneDirector 3000 Firmware – 10.2.1.0.218
Ruckus Wireless ZoneDirector 5000 Firmware – 10.0.1.0.151
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Protocol Tunneling
Internal Proxy
Web Protocols
DNS
Mail Protocols
File Transfer Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Chinese APT exploiting networking devices creates ORB infrastructure targeting telecom routers, enabling lateral movement and encrypted traffic interception for espionage operations.
Government Administration
State-sponsored LONGLEASH malware compromises internet-facing devices to establish covert relay networks, facilitating government network infiltration and sensitive data exfiltration.
Computer Networking
UAT-7810 specifically targets Ruckus and ASUS routers using n-day vulnerabilities, creating persistent backdoors that compromise network infrastructure and enable traffic redirection.
Health Care / Life Sciences
ORB network infrastructure enables encrypted traffic interception and east-west lateral movement, threatening HIPAA compliance and patient data security in healthcare networks.
Sources
- Chinese hackers develop LONGLEASH malware to expand ORB networkhttps://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/Verified
- UAT-7810 Expands LapDogs ORB Network With LONGLEASH and New Router Malwarehttps://www.mallory.ai/stories/019f3c0f-b6fd-7303-9cc8-0eb687f4ffa1Verified
- UAT-7810 continues building ORB networks using new malwarehttps://radar.offseq.com/threat/uat-7810-continues-building-orb-networks-using-new-131a9e82a8e2a441Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in unpatched routers would likely be constrained by enforcing strict access controls and continuous verification of device integrity.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and establish persistence would likely be constrained by enforcing strict segmentation policies that limit access to critical systems.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained by enforcing east-west traffic controls that limit unauthorized inter-workload communication.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained by providing comprehensive visibility and control over multicloud environments, detecting and disrupting unauthorized communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained by enforcing strict egress policies that monitor and control outbound traffic.
The attacker's ability to expand their network and conduct further malicious activities would likely be constrained by limiting the blast radius through strict segmentation and continuous monitoring.
Impact at a Glance
Affected Business Functions
- Network Operations
- IT Security Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of network configurations and access credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement regular patch management to address known vulnerabilities in networking devices.
- • Deploy Zero Trust Segmentation to limit lateral movement within the network.
- • Utilize East-West Traffic Security to monitor and control internal traffic flows.
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to malicious activities promptly.



