ShortLeash is a custom backdoor associated with the LapDogs operational relay box network, a large-scale compromise of internet-facing SOHO and edge devices assessed to support China-nexus espionage operations. It is primarily deployed on Linux-based routers and similar embedded systems, especially unpatched Ruckus and Buffalo devices, and has also been linked to a Windows sample, indicating at least some cross-platform development or staging. The malware is designed to establish a durable foothold on compromised devices and incorporate them into relay infrastructure that can be used to proxy attacker activity, obscure origin, and potentially enable follow-on access into connected internal networks.
On infected Linux systems, ShortLeash is installed with root privileges and persists through a malicious system service mechanism that survives reboot. It runs a server on the compromised device, mimics Nginx responses, and generates a unique self-signed TLS certificate per node using spoofed LAPD-themed metadata. The implant contains encrypted and compressed configuration data and communicates with command-and-control infrastructure over HTTPS. Reported functionality includes command-and-control communications, web server hosting, tunnel management, and operation as both a command-and-control server and client, making it suitable for operational relay box use rather than simple single-host persistence.
ShortLeash has been tied to the LapDogs campaign, which has infected more than a thousand devices globally since at least 2023, with concentrations in the United States, Japan, South Korea, Hong Kong, and Taiwan. Victims have included organizations in sectors such as IT, networking, real estate, media, and municipal services. Multiple assessments link the broader activity to China-nexus operators, with moderate-confidence reporting that infrastructure enabled operations associated at least once with UAT-5918, while later reporting attributes ongoing LapDogs development and expansion to UAT-7810, which appears to maintain relay infrastructure for secondary actors. ShortLeash is now assessed to be succeeded or extended by the more capable LONGLEASH variant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 | As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year.
Campaigns observed earlier this year have also singled out ASUS AiCloud Routers susceptible to CVE-2025-2492, indicating potential attempts to broaden the ORB network.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LapDogs employs a custom backdoor we named "ShortLeash," which establishes a foothold on compromised devices and connects them within the network.
LONGLEASH : Nouvelle version de SHORTLEASH, nommée en interne “ff-agent” et “nz1.0”.
LapDogs leverages a custom backdoor ("ShortLeash") with unique self-signed TLS certificates mimicking LAPD metadata, focusing on Linux-based SOHO devices (notably Ruckus and Buffalo routers).
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
Forensic evidence such as developer notes written in Mandarin in a custom backdoor SecurityScorecard named "ShortLeash," plus tools, techniques and procedures "strongly supports" attribution to a Chinese actor.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The script begins by assessing the privileges of the local user, insisting on being a root level user to run the script.
The report describes a threat actor that achieves initial access by exploiting unpatched vulnerabilities in internet-exposed web and application servers... A large proportion of the IPs within the network are specifically vulnerable to CVE-2015-1548 and CVE-2017-17663...
The script begins by assessing the privileges of the local user, insisting on being a root level user to run the script.
It then checks whether the operating system is Ubuntu or CentOS... target the relevant folder... /etc/systemd/system/ in Ubuntu and /lib/systemd/system/ in CentOS... This service is then interpreted by the system daemon. It is enabled to run in the background... and to be reloaded on a reboot, ensuring persistence and startup survivability.
The script begins by assessing the privileges of the local user, insisting on being a root level user to run the script.
It then checks whether the operating system is Ubuntu or CentOS... target the relevant folder... /etc/systemd/system/ in Ubuntu and /lib/systemd/system/ in CentOS... This service is then interpreted by the system daemon. It is enabled to run in the background... and to be reloaded on a reboot, ensuring persistence and startup survivability.
The payload... runs a server on the infected system and simulates Nginx responses... ShortLeash creates a fake Nginx web server and locally generates a unique, self-signed, TLS certificate presenting as “LAPD”.
The aforementioned PE was available on the VirusTotal platform... attempts to establish encrypted communication with a hardcoded domain at www[.]northumbra[.]com, supposedly its C2 server...
Sandbox data... recorded attempts to establish encrypted communication with a hardcoded domain... via numerous HTTPS POST requests with various added parameters.
This type of infrastructure ... allows threat actors to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution.
ORB Networks are made up of Virtual Private Servers (VPSs) and a series of compromised devices... Hackers that use ORB Networks use the various devices as their proxies and rely on them for obfuscation.
Talos identified three known vulnerabilities that UAT-7810 has exploited to break into these devices since 2025... IP Address 194.233.92[.]26 VPS server used to host malicious payloads
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier backdoor variant referenced as the predecessor to LONGLEASH.
An earlier backdoor used to infect SOHO routers in the LapDogs espionage infrastructure campaign. LongLeash builds on functionality previously observed in ShortLeash.
Custom malware used by UAT-7810 as part of its ORB operations. It includes a backdoor capable of contacting an external server, hosting a web server, and acting as both a command-and-control server and client.
A custom backdoor used by UAT-7810 on compromised devices, apparently an earlier version being superseded by LONGLEASH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.