Chinese hackers develop LONGLEASH malware to expand ORB network
IncidentRuckus routersUAT-7810ASUS AiCloud routersOur summary
Researchers at Cisco Talos say a China-aligned actor tracked as 'UAT-7810' is expanding its Operational Relay Box (ORB) infrastructure by compromising internet-exposed networking devices, with a focus on unpatched Ruckus routers. The campaign includes new malware components such as LONGLEASH (an upgraded SHORTLEASH backdoor) and others, and the initial access targets multiple vulnerabilities including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 (as well as similar issues in ASUS AiCloud devices). This matters because ORB networks can proxy malicious traffic through seemingly legitimate local infrastructure, making detection and attribution significantly harder.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.