UAT-7810 is a China-nexus advanced persistent threat actor focused on building, maintaining, and expanding Operational Relay Box (ORB) infrastructure, most notably the LapDogs network. Rather than concentrating primarily on end-target intrusion objectives, the group appears to function as an infrastructure and initial-access provider for other China-aligned espionage actors, including UAT-5918, while remaining a distinct cluster despite tooling overlap. The actor specializes in compromising internet-facing networking and edge devices, especially unpatched Ruckus wireless routers, and has also been linked to exploitation of ASUS AiCloud router vulnerabilities. Its operations rely on known n-day vulnerabilities rather than publicly described zero-days. After compromise, UAT-7810 repurposes devices into relay nodes that proxy malicious traffic, obscure operator origin, and support downstream reconnaissance, command-and-control, malware delivery, and exfiltration activity by secondary actors. UAT-7810 maintains a bespoke malware ecosystem tailored to embedded and Linux-based environments across multiple architectures including MIPS, ARM, and x64. Associated malware families include SHORTLEASH and its successor LONGLEASH, the passive Linux backdoor DOGLEASH, the Java-based administrative backdoor JARLEASH, and the testing utility LEASHTEST. LONGLEASH extends earlier functionality with reverse shell access, multi-protocol proxying, packet redirection, tunnel management, intermediate command-and-control forwarding, SMTP functionality, TLS/PKI handling, client authorization, and self-removal when tampering is detected. DOGLEASH supports shellcode or command execution, file operations, and host information collection. JARLEASH provides web-based file management and file-transfer or listener capabilities useful for administration of compromised systems and actor-controlled servers. LEASHTEST is used to validate functionality on MIPS and IoT-class devices, reflecting ongoing development for heterogeneous router and embedded-device environments. Available attribution reporting assesses UAT-7810 with high confidence as a Chinese-speaking, China-aligned actor. Its role in sustaining renewable relay infrastructure makes it a significant enabler of broader Chinese espionage operations by helping affiliated actors blend malicious traffic with legitimate residential and small-business edge infrastructure and complicating attribution and blocking.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network.
217.15.164.147 a également été utilisée pour exploiter CVE-2025-2492 (ASUS AiCloud Routers) début 2026. UAT-7810 cible principalement des routeurs Ruckus non patchés via : CVE-2020-22653 CVE-2020-22658 CVE-2023-25717 CVE-2025-2492 (ASUS AiCloud)
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised Ruckus edge devices via multiple CVEs and expanded the LapDogs ORB network to provide operational relay infrastructure supporting other China-nexus actors.
Maintains and expands the LapDogs ORB network, using compromised SOHO routers and edge devices as relay infrastructure for espionage logistics such as proxying, tunneling, traffic redirection, and intermediate C2 behavior.
China-nexus actor assessed with high confidence as responsible for building and proliferating ORB networks that can be used by secondary actors. The report documents its evolving malware arsenal and exploitation of internet-facing routers.
China-linked espionage actor operating an ORB network by compromising SOHO routers and expanding its toolkit with LongLeash, DogLeash, and JarLeash backdoors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.