JARLEASH is a Java-based backdoor and administrative tool associated with the China-nexus threat actor UAT-7810 and its LapDogs operational relay box (ORB) activity. It has been deployed both on attacker-controlled infrastructure and on compromised systems to provide convenient remote administration. Reported functionality includes a web-based file management interface as well as embedded FTP, SFTP, and Netcat server capabilities, enabling operators to manage files and transfer data on systems under their control. JARLEASH has been described as part of a broader custom malware ecosystem that also includes LONGLEASH, DOGLEASH, and LEASHTEST.
UAT-7810 is assessed to specialize in building and maintaining ORB infrastructure composed largely of compromised edge devices and routers, especially unpatched Ruckus wireless routers, with additional activity involving ASUS AiCloud routers. Within that ecosystem, JARLEASH appears to serve an administrative and post-compromise support role rather than the router-focused relay role attributed to LONGLEASH. It has been observed on at least some compromised servers used in the actor’s infrastructure, where it supports server management and operator access. Configuration artifacts reportedly contained Simplified Chinese comments, consistent with broader assessments linking the activity to Chinese-speaking operators.
JARLEASH is best understood as a lightweight Java backdoor used for administration, file handling, and service exposure in support of long-term infrastructure operations tied to China-aligned espionage enablement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-7810 targeted unpatched Ruckus wireless routers and ASUS AiCloud routers to deploy LONGLEASH, DOGLEASH, and JARLEASH, thereby establishing an ORB network.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
The backdoor can host a web-based file management interface and FTP and SFTP servers, and can run a netcat server on a provided IP and port number.
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed to compromised routers to establish an ORB network.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Java JAR backdoor deployed on attacker infrastructure and compromised systems, offering web-based file management plus FTP/SFTP and Netcat-style server capabilities.
A Java-based backdoor used to access compromised systems. It is deployed with a script that kills other instances before spawning a Java container, and it can host a web-based file management interface, FTP and SFTP servers, and run a netcat server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.