threat-intel
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
High
Summary
A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group leverages vulnerabilities in devices like Ruckus and ASUS routers to deploy these tools and conduct attacks, particularly targeting Taiwan’s critical infrastructure. This ongoing development and testing indicates a continued focus on expanding their capabilities and targeting embedded systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
