LONGLEASH is a router-focused backdoor used by the China-nexus threat actor UAT-7810 in support of the LapDogs Operational Relay Box (ORB) network. It is an evolved successor to SHORTLEASH and is associated with campaigns targeting unpatched edge devices, particularly Ruckus wireless routers, with related activity also linked to ASUS AiCloud router exploitation via CVE-2025-2492. UAT-7810 is assessed to use this tooling primarily to build and maintain relay infrastructure that can be leveraged by other China-aligned espionage actors, including UAT-5918, rather than solely for direct victim operations.
LONGLEASH was compiled for MIPS and is built on the same codebase lineage as SHORTLEASH, with reported use of components such as Boost.Asio, Nanopb, and MbedTLS. It substantially expands earlier functionality by supporting reverse shell access, multi-protocol proxying across HTTP, DNS, SOCKS, TCP, ICMP, and UDP, packet redirection, SMTP client and server functions, TLS and PKI management, tunnel handling, client authorization, and operation as an intermediate command server that relays commands and data between upstream controllers and peer nodes. It can also host web services on compromised devices and includes self-removal behavior when tampering or suspicious activity is detected. These features make it well suited for turning compromised routers and embedded systems into durable relay nodes for command-and-control, traffic forwarding, and broader ORB operations.
The malware is part of a broader UAT-7810 ecosystem that also includes DOGLEASH, JARLEASH, and LEASHTEST, with payloads observed across MIPS, ARM, and x64 environments. LONGLEASH is most strongly associated with Linux-based embedded and networking platforms used as covert infrastructure rather than traditional enterprise endpoints. Its role in proxying, encrypted tunneling, and relaying traffic aligns with long-term persistence and defense-evasion objectives in state-linked espionage support operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-7810 targeted unpatched Ruckus wireless routers and ASUS AiCloud routers to deploy LONGLEASH, DOGLEASH, and JARLEASH, thereby establishing an ORB network.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
T1095 — Non-Application Layer Protocol (Command and Control)
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed to compromised routers to establish an ORB network.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Backdoor for MIPS devices and IoT-style targets that provides reverse shell access, multiple proxying modes, packet forwarding, SMTP server/client functionality, TLS/PKI handling, and self-deletion when detection is suspected.
A newer backdoor derived from ShortLeash that supports command-and-control communication, web server hosting, tunnel management, and can act as both C&C and client. It can also function as an intermediate server, forwarding commands and data from the C&C to other peers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.