DOGLEASH is a lightweight Linux backdoor written in C and associated with the China-nexus threat actor UAT-7810. It has been used in the LapDogs Operational Relay Box ecosystem alongside LONGLEASH, JARLEASH, and LEASHTEST to support the compromise and operational use of edge infrastructure, particularly routers and other embedded Linux devices. UAT-7810 has been assessed as an infrastructure-focused actor that builds and maintains relay networks for downstream espionage activity, including support to other China-aligned operators such as UAT-5918.
DOGLEASH is deployed post-compromise via shell scripts on infected Linux systems. Those scripts have been observed modifying local firewall rules to permit inbound TCP traffic to the port on which the implant listens. The malware operates as a passive backdoor, quietly binding to a hardcoded TCP port and waiting for authenticated inbound requests. Reported functionality includes execution of arbitrary shellcode or in-memory code, shell command execution, file reading, file renaming, closing its listener, and collection of operating system information. Its design is consistent with post-exploitation access on compromised Linux-based networking devices rather than broad commodity malware deployment.
The malware has been observed in campaigns targeting unpatched Ruckus wireless routers and ASUS AiCloud routers as part of efforts to expand ORB infrastructure. Variants have been hosted for multiple architectures including MIPS, ARM, and x64, reflecting use across routers, embedded devices, and standard Linux systems. Within the broader UAT-7810 toolchain, DOGLEASH appears to provide quiet, low-footprint access and code-execution capability on compromised nodes that can then be incorporated into relay infrastructure or used for follow-on operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-7810 targeted unpatched Ruckus wireless routers and ASUS AiCloud routers to deploy LONGLEASH, DOGLEASH, and JARLEASH, thereby establishing an ORB network.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
CISA and international partners described the broader pattern in April 2026: China-nexus actors using large-scale covert networks of compromised SOHO routers, IoT devices, and smart devices across reconnaissance, malware delivery, C2, and exfiltration.
Cisco Talos reported that UAT-7810 continues to maintain and expand the LapDogs ORB network with router-focused malware families and tooling such as LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
The reporting describes capabilities aligned to relay operations: proxying, tunneling, traffic redirection, node authorization, intermediate C2 behavior...
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed to compromised routers to establish an ORB network.
Router-focused malware/tooling used to support the LapDogs ORB network, with capabilities aligned to relay operations including proxying, tunneling, traffic redirection, node authorization, and intermediate C2 behavior across multiple architectures.
Passive Linux backdoor written in C that listens on a hardcoded TCP port and can execute arbitrary shellcode, read and rename files, and collect operating system information.
A C-based passive backdoor deployed by shell script. It can execute commands, read and rename files, close its socket listener, retrieve OS information, and execute code in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.