ShortLeash is a custom backdoor used to establish persistent access on compromised SOHO and edge devices and enroll them in the LapDogs operational relay box (ORB) network. It primarily targets Linux-based routers and access points, particularly Ruckus and Buffalo devices, and Windows variants have also been identified. On supported Linux systems, it uses root-level startup execution and a system service to persist across reboots. The implant runs a server that mimics Nginx behavior, communicates with command-and-control infrastructure over encrypted web traffic, manages tunnels, and can operate as both a command-and-control client and server. Each infected node generates a distinct self-signed TLS certificate containing spoofed LAPD-themed metadata, supporting masquerading and identification of individual ORB nodes. LapDogs nodes can proxy attacker traffic and may provide a route into connected internal networks while the compromised device continues normal operation. ShortLeash has been deployed following exploitation of known vulnerabilities in unpatched internet-facing networking devices. LapDogs activity has been assessed as China-nexus; UAT-7810 is associated with maintaining and expanding the network, while UAT-5918 has been assessed as a possible downstream user in operations targeting Taiwanese critical infrastructure. LONGLEASH is a more capable successor developed from the ShortLeash codebase.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
Campaigns observed earlier this year have also singled out ASUS AiCloud Routers susceptible to CVE-2025-2492, indicating potential attempts to broaden the ORB network.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
LONGLEASH : Nouvelle version de SHORTLEASH, nommée en interne “ff-agent” et “nz1.0”.
LapDogs leverages a custom backdoor ("ShortLeash") with unique self-signed TLS certificates mimicking LAPD metadata, focusing on Linux-based SOHO devices (notably Ruckus and Buffalo routers).
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Annex B lists "Boot or Logon Initialisation Scripts: Linux and Unit" under Persistence.
The script begins by assessing the privileges of the local user, insisting on being a root level user to run the script.
It then checks whether the operating system is Ubuntu or CentOS... target the relevant folder... /etc/systemd/system/ in Ubuntu and /lib/systemd/system/ in CentOS... This service is then interpreted by the system daemon. It is enabled to run in the background... and to be reloaded on a reboot, ensuring persistence and startup survivability.
Annex B lists "Boot or Logon Initialisation Scripts: Linux and Unit" under Persistence.
Annex B lists Exploitation for Privilege Escalation under Privilege Escalation.
The script begins by assessing the privileges of the local user, insisting on being a root level user to run the script.
It then checks whether the operating system is Ubuntu or CentOS... target the relevant folder... /etc/systemd/system/ in Ubuntu and /lib/systemd/system/ in CentOS... This service is then interpreted by the system daemon. It is enabled to run in the background... and to be reloaded on a reboot, ensuring persistence and startup survivability.
The payload... runs a server on the infected system and simulates Nginx responses... ShortLeash creates a fake Nginx web server and locally generates a unique, self-signed, TLS certificate presenting as “LAPD”.
Immediately after defining the OS, the script will create a backup of the existing malicious .service file within the same directory, naming the new one “ff-agent-pi.service” and the backup “ff-agent-pi.service_bak.”
Annex B lists Indicator Removal on Host: File Deletion under Defense Evasion.
The aforementioned PE was available on the VirusTotal platform... attempts to establish encrypted communication with a hardcoded domain at www[.]northumbra[.]com, supposedly its C2 server...
Annex B lists Application Layer Protocol: Web Protocols under Command and Control.
This type of infrastructure ... allows threat actors to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution.
ORB Networks are made up of Virtual Private Servers (VPSs) and a series of compromised devices... Hackers that use ORB Networks use the various devices as their proxies and rely on them for obfuscation.
Talos identified three known vulnerabilities that UAT-7810 has exploited to break into these devices since 2025... IP Address 194.233.92[.]26 VPS server used to host malicious payloads
SHORTLEASH consisted of a backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels... LONGLEASH... supports... setting and management of basic network tunnels.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier backdoor variant referenced as the predecessor to LONGLEASH.
An earlier backdoor used to infect SOHO routers in the LapDogs espionage infrastructure campaign. LongLeash builds on functionality previously observed in ShortLeash.
Custom malware used by UAT-7810 as part of its ORB operations. It includes a backdoor capable of contacting an external server, hosting a web server, and acting as both a command-and-control server and client.
A custom backdoor used by UAT-7810 on compromised devices, apparently an earlier version being superseded by LONGLEASH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.