Project ORBITAL, a new open-source intelligence initiative, has been launched to track and analyze Operational Relay Box (ORB) networks that advanced persistent threat actors use to hide command-and-control activity behind layers of compromised end-of-life SOHO routers and IoT devices. The project aggregates public reporting and telemetry from security vendors and U.S. government agencies into a centralized intelligence matrix and graph view, reflecting growing industry focus on ORB infrastructure as a durable method for obscuring attacker origin and blending malicious traffic with legitimate regional traffic.
The reporting says ASUS devices appear most frequently in public ORB disclosures, while the LapDogs ORB network has the highest number of reported targeted devices. It also identifies overlap in ORB usage among China-linked actors including APT15, UNC2630, and UNC5174, indicating some infrastructure may be provisioned by specialized teams and then shared or leased across a broader Chinese espionage ecosystem. The findings reinforce that ORB networks are no longer a niche tradecraft element but a standard operational security layer for multiple Chinese-linked intrusion sets.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
A report alleged that Guangdong Chanming develops offensive cyber capabilities for Chinese state customers and likely supplied RedRelay-related infrastructure to Chinese military and security entities. It also linked Guangdong Chanming and the FCN tool to WHIPWEAVE, a malware component of the RedRelay/ORBWEAVER covert network, and aligned the users with the APT15/Ke3chang cluster.
The Project ORBITAL analysis reported overlap in ORB usage among Chinese-linked actors including APT15, UNC2630, and UNC5174. It suggested some ORB infrastructure may be provisioned by specialized teams and shared or leased across the broader Chinese intelligence ecosystem.
Project ORBITAL's analysis identified ASUS devices as the most frequently targeted devices appearing in public ORB reporting. The same analysis found the LapDogs ORB network had the highest number of reported targeted devices.
Project ORBITAL was launched as an open-source intelligence initiative to track and analyze Operational Relay Box (ORB) networks used by advanced persistent threat actors. It aggregates public reporting and telemetry from security vendors and U.S. government agencies into a centralized intelligence matrix and graph visualization.
Trend Micro reported that the Sandworm-attributed Cyclops Blink botnet, previously known for infecting WatchGuard Firebox devices, was also infecting ASUS routers. The report described the malware's persistence in flash memory, modular architecture, and use of compromised routers as C2 infrastructure, with more than 200 victims identified globally.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcepylos.co
Open sourceteam-cymru.com
Open sourceblog.bushidotoken.net
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.