LapDogs is a China-linked espionage operation centered on an operational relay box (ORB) network composed of more than 1,000 compromised small-office/home-office routers and IoT devices. The campaign has been active since at least September 2023 and is associated with the compromise of end-of-life Linux-based edge devices using known vulnerabilities. After exploitation, operators deploy the ShortLeash backdoor to maintain access and use the infected infrastructure as a relay network in support of espionage activity. The operation demonstrates capabilities in initial access, persistence, defense evasion, and post-exploitation through the covert use of backdoored network appliances as intermediary infrastructure. Publicly available information supports a China nexus and an intelligence-gathering purpose, but does not provide high-confidence attribution to a specific named intrusion set or sufficient detail on distinct sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.