CVE Tools

Chinese hackers develop LONGLEASH malware to expand ORB network

BleepingComputerBy Bill Toulas

IncidentRuckus routersUAT-7810ASUS AiCloud routers

Our summary

Researchers at Cisco Talos say a China-aligned actor tracked as 'UAT-7810' is expanding its Operational Relay Box (ORB) infrastructure by compromising internet-exposed networking devices, with a focus on unpatched Ruckus routers. The campaign includes new malware components such as LONGLEASH (an upgraded SHORTLEASH backdoor) and others, and the initial access targets multiple vulnerabilities including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 (as well as similar issues in ASUS AiCloud devices). This matters because ORB networks can proxy malicious traffic through seemingly legitimate local infrastructure, making detection and attribution significantly harder.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store