China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Reported exploitedRuckus wireless routersUAT-7810Asus AiCloud RoutersOur summary
A China-linked APT group, tracked as UAT-7810, has expanded its toolkit with new backdoor variants targeting SOHO routers from Ruckus and Asus. Researchers at Cisco Talos have uncovered updated malware families—LongLeash, DogLeash, and JarLeash—that exploit known vulnerabilities such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. These tools enable attackers to maintain persistent access, manage tunnels, and execute remote commands. The threat actor is also linked to a broader espionage campaign involving thousands of compromised devices.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.