China-Linked APT Uses Ruckus and ASUS Router Flaws to Expand ORB Infrastructure

Advanced persistent threat actors are aggressively leveraging compromised networking devices to build sophisticated relay networks for cyberattacks against high-value targets.

The threat actor formally tracked as UAT-7810 continues to actively proliferate the LapDogs Operational Relay Box network, an infrastructure designed to anonymize external malicious traffic effectively.

Cisco Talos said in a report shared with Cyber Security News (CSN) that UAT-7810 is highly likely a China-nexus group, based directly on the foundational infrastructure it provides to other regional threat actors.

Despite demonstrating overlapping custom tools with prominent groups like UAT-5918, these entities maintain completely separate operational objectives, targets, and strategic deployment methodologies across the cyber threat landscape.

China APT Expands ORB

To effectively facilitate this large-scale network expansion, the attackers rely heavily on exploiting n-day vulnerabilities across popular edge networking hardware platforms.

The primary focus remains strictly on unpatched Ruckus wireless routers, a proven tactical approach the group has consistently used since its initial discovery.

Within these ongoing campaigns, the operators actively exploit known vulnerabilities, formally tracked as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, to gain unauthorized access to target devices.

Recent forensic investigations indicate an aggressive push into entirely new territory, with threat actors deliberately targeting ASUS AiCloud routers through direct exploitation of CVE-2025-2492.

This device diversification illustrates a concerted effort to scale their operational relay infrastructure across multiple hardware ecosystems.

Startup script for SHORTLEASH (Source: talosintelligence)
Startup script for SHORTLEASH (Source: talosintelligence)

A security researcher analyzing the newly acquired operational infrastructure discovered four new remote servers hosting malicious payloads tailored for MIPS, ARM, and x64 architectures.

Three distinct primary IP addresses were definitively identified as initial download locations.

The sustained operational success of UAT-7810 relies on the continuous development of bespoke malicious tooling, most notably the significant transition from their original SHORTLEASH implant to a highly upgraded variant, LONGLEASH.

Built on the same foundational application codebase, LONGLEASH incorporates advanced networking capabilities that enable it to function as an intermediate command-and-control proxy server immediately.

Startup script for JARLEASH (Source: talosintelligence)
Startup script for JARLEASH (Source: talosintelligence)

The advanced implant utilizes the asynchronous version of the Boost application library on specific MIPS processors to minimize transmission blocking time and maximize network proxy performance.

Furthermore, it incorporates open-source software components such as Nanopb for processing structured protocol buffer messages and MbedTLS for secure encrypted communications, talosintelligence said.

Beyond deploying the primary network implant framework, the threat actors have expanded their daily operational toolkit with two previously undocumented backdoors tracked internally as DOGLEASH and JARLEASH.

DOGLEASH functions flawlessly as a passive digital backdoor specifically designed for deeply compromised Linux operating environments.

Upon successful execution via automated startup scripts, it modifies native device firewall rules to permanently bind and listen on a hardcoded transmission port, awaiting encrypted TCP network requests that trigger specialized application threads.

Conversely, JARLEASH operates seamlessly as a versatile Java-based remote administrative tool deployed selectively on the attackers’ own routing infrastructure, utilizing specialized network configurations written entirely in Simplified Chinese characters.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories