LapDogs is a China-nexus operational relay box network centered on the compromise of internet-facing Linux-based SOHO and edge networking devices, particularly routers. It is associated with the threat actor UAT-7810, which has been assessed as responsible for maintaining and expanding the infrastructure, likely for use by other China-aligned intrusion actors including UAT-5918. The network emerged publicly in 2025 and has been linked to activity focused on the United States and Southeast Asia.
LapDogs relies on a bespoke Linux backdoor family known as ShortLeash, with later evolution into LONGLEASH, reflecting active development. ShortLeash supports covert command-and-control, can host a web server on a compromised device, and can function as both a command-and-control client and server. LONGLEASH extends this design with relay and proxy capabilities over multiple protocols, allowing compromised nodes to operate as intermediate command-and-control infrastructure that forwards commands and data between upstream controllers and peer nodes. Reported companion tooling includes DOGLEASH, a passive backdoor capable of executing arbitrary shellcode on compromised Linux devices; LEASHTEST, used to validate functionality on MIPS-based embedded systems; and JARLEASH, a Java-based administration backdoor supporting file management and remote transfer functions.
The malware ecosystem is used to convert compromised routers and similar devices into covert relay infrastructure that obscures backend operator systems and supports follow-on espionage operations. Persistence has been observed through privileged service configuration on Linux systems, and the operators have used unique self-signed TLS certificates designed to blend in with expected metadata. LONGLEASH also includes anti-tampering behavior, including the ability to remove the implant and traces if interference is detected.
Observed intrusion activity tied to LapDogs has exploited known vulnerabilities in unpatched Ruckus devices, and related campaigns have also targeted ASUS AiCloud routers to broaden the relay network. The overall role of LapDogs is not conventional disruptive botnet activity, but stealthy post-compromise infrastructure support: maintaining persistent access, relaying traffic, and enabling covert command-and-control for broader China-linked espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"It leverages the proprietary AiCloud service with n-day vulnerabilities in order to gain high privileges on End-Of-Life ASUS WRT routers" ... "The attacks likely exploit vulnerabilities tracked as CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, CVE-2023-41348, CVE-2024-12912, and CVE-2025-2492 for proliferation."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An operational relay box network built from compromised edge devices and used to relay traffic in support of China-nexus operations.
An Operational Relay Box (ORB) network maintained and expanded by UAT-7810 through compromises of internet-facing networking devices, intended to provide relay infrastructure for follow-on malicious operations.
A router-focused ORB-style malware/network that compromises devices via n-day vulnerabilities to build relay and scanning infrastructure.
Mentioned as a comparative router ORB/botnet abusing vulnerable devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.