Winning 54% of the time
Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom malware, including LONGLEASH and DOGLEASH, to establish covert networks for other APT groups. These ORB networks create a blind spot, allowing secondary actors to mask their origins and route malicious traffic, and the group is heavily investing in developing sophisticated, multi-platform tools. Defenders should prioritize patching Ruckus and ASUS routers and monitoring for proxying behavior.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
