Do you have an ASUS router? Check the firmware right now. We tell you how not to become a free intermediary in the dismantling of world special servic

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
242
Reaction score
305
Deposit
0$
Cisco Talos specialists have revealed new details about the UAT-7810 group, which is developing the LapDogs ORB network and infects routers so that other groups associated with China can hide their own operations through them.





According to Talos, the UAT-7810 does not just hack into individual devices, but builds infrastructure to then attack valuable targets. This scheme allows you to use infected routers as intermediate nodes through which malicious traffic passes. As a result, real sources of attacks are more difficult to track, and conventional network devices become part of someone else’s infrastructure.





The group continues to refine its own tools. Talos has discovered a new version of the previously known malware SHORTLEASH and tracks it as LONGLEASH. The new option has learned to better proxy traffic, create network tunnels, work with encrypted connections and transfer commands between nodes. LONGLEASH can also act as an intermediate control server, receiving data from the main control center and forwarding them to other infected devices.





In the arsenal of UAT-7810 found two previously unknown malware. DOGLEASH is a hidden login for devices on Linux and allows commands to execute, read files, make backups and run the code right in memory. JARLEASH is written in Java and is able to control files, run FTP and SFTP servers, and also provide remote access through network tools. In the JARLEASH configuration, experts found comments in a simplified Chinese language.










The main goal of the group remains unused network devices. Talos connects UAT-7810 with the fact that the group exploits known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653 (9.8 Critical), CVE-2020-22658 (9.8 Critical) and CVE-2023-25717 (10 Critical). One of the addresses was also used in early 2026 in attacks on ASUS AiCloud routers via CVE-2025-2492 (9.7 Critical), which may indicate an attempt to expand the network of infected nodes.





Talos identified four new servers from which attackers distributed malicious files to different hardware platforms, including MIPS, ARM and x64. On the compromised devices, scripts were launched that downloaded DOGLEASH and opened the desired port for incoming connections. A separate LEASHTEST test file helped to check the basic functions on devices with MIPS processors - this shows that the tools continue to be configured for embedded systems.





Talos connects UAT-7810 with a high degree of confidence with the Chinese direction, but separates the group from UAT-5918. According to the company, the UAT-7810 is probably responsible for creating the infrastructure, and related groups are already using trained nodes to carry out their own attacks.
 
Top Bottom