UAT-7810 is a China-nexus advanced persistent threat actor focused on building, maintaining, and expanding Operational Relay Box (ORB) infrastructure, most notably the LapDogs network. Rather than being primarily associated with direct victim-end espionage collection, the group is assessed to function as an infrastructure and initial-access provider that enables other China-aligned actors, including UAT-5918, to route operations through compromised edge devices and obscure the origin of downstream activity. Talos has treated UAT-7810 and UAT-5918 as distinct clusters despite tooling overlap. The actor has shown a sustained preference for compromising internet-facing networking equipment, especially unpatched Ruckus wireless routers, and has also been linked to exploitation of ASUS AiCloud routers. Reported exploitation includes CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492. After gaining access, UAT-7810 repurposes compromised devices as relay nodes within ORB infrastructure used for proxying, tunneling, traffic redirection, intermediate command-and-control, reconnaissance support, malware delivery, and exfiltration support for broader China-linked operations. UAT-7810 maintains a bespoke malware ecosystem centered on router- and Linux-focused tooling. Known malware families and utilities include SHORTLEASH, its successor LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. LONGLEASH is an evolved backdoor that supports reverse shell access, multi-protocol proxying, packet redirection, tunnel management, SMTP functionality, TLS/PKI handling, client authorization, and self-removal when tampering is detected. It can also operate as an intermediate C2 node forwarding commands and data between peers. DOGLEASH is a passive Linux backdoor capable of file operations, system information collection, shell command execution, and arbitrary shellcode execution in memory. JARLEASH is a Java-based administrative backdoor that provides web-based file management and can run FTP, SFTP, and Netcat services on compromised systems or actor-controlled infrastructure. LEASHTEST is a testing utility used to validate functionality on MIPS and embedded IoT platforms, reflecting active development for heterogeneous edge-device environments. The actor’s tooling has been observed across MIPS, ARM, and x64 architectures, reinforcing the assessment that UAT-7810’s operational objective is to convert routers, embedded devices, and related edge systems into durable relay infrastructure rather than merely achieve one-off code execution. Simplified Chinese comments identified in JARLEASH configuration data further support assessment of Chinese-speaking operators. UAT-7810 is best characterized as a China-aligned ORB builder and infrastructure enabler supporting long-term espionage logistics, concealment, and operational resilience for related threat activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromising unpatched routers to deploy malware and build an ORB network.
Compromised Ruckus edge devices via multiple CVEs and expanded the LapDogs ORB network to provide operational relay infrastructure supporting other China-nexus actors.
Maintains and expands the LapDogs ORB network, using compromised SOHO routers and edge devices as relay infrastructure for espionage logistics such as proxying, tunneling, traffic redirection, and intermediate C2 behavior.
China-nexus actor assessed with high confidence as responsible for building and proliferating ORB networks that can be used by secondary actors. The report documents its evolving malware arsenal and exploitation of internet-facing routers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.