threat-intel
UAT-7810 continues building ORB networks using new malware
High
Summary
Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants, including LONGLEASH (a successor to SHORTLEASH), and leveraging unpatched vulnerabilities in devices like Ruckus wireless routers and ASUS AiCloud Routers to expand its network. Talos has tracked UAT-7810 using multiple servers across Hong Kong and other locations to host malicious payloads and conduct exploitation activities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
