A China-linked threat actor, UAT-7810, is actively expanding its network of Operational Relay Boxes (ORBs) by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers. The group is deploying a new set of custom malware, including updated versions of the "LONGLEASH" and "DOGLEASH" backdoors, to establish covert infrastructure for other advanced persistent threat (APT) groups.
These ORB networks are designed to obscure the origins of secondary threat actors, allowing them to route malicious traffic through seemingly legitimate nodes. By compromising edge devices such as wireless routers, UAT-7810 creates a highly evasive and decentralized proxy network that can bypass conventional perimeter defenses.
The development of sophisticated, multi-platform tools like LONGLEASH indicates a significant investment by UAT-7810 in building resilient and difficult-to-dismantle infrastructure. This strategy creates substantial blind spots for defenders, making it harder to trace and mitigate attacks.
Security researchers emphasize that UAT-7810's reliance on exploiting n-day vulnerabilities highlights the critical need for organizations to ensure all edge devices, particularly Ruckus and ASUS routers, are fully patched. Defenders should also monitor network traffic for any unusual proxying behavior or unauthorized connections on devices that typically do not host complex services.
The ongoing activity of UAT-7810 underscores the continuous challenge in cybersecurity, where attackers only need to succeed once while defenders must maintain constant vigilance. This asymmetry is often compared to a tennis match, where winning individual points doesn't guarantee victory; rather, strategic decisions and adapting to an opponent's moves are crucial.
In a similar vein, cybersecurity operations involve thousands of judgment calls, where context and environmental understanding enable better decision-making. The goal is not perfection, which is often unattainable, but rather to make informed choices that improve defensive posture against persistent threats.
In other recent cybersecurity news, researchers have documented what they describe as the first instance of "agentic ransomware," though it functioned more as a wiper due to non-reversible encryption. This attack still required human involvement for tasks such as providing compromised credentials, provisioning command-and-control servers, and selecting victims.
Separately, six security flaws were discovered in Apple's AirDrop and Google's Quick Share. These vulnerabilities allow an attacker within wireless range, using only a laptop and no prior connection, to crash the sharing service on a Mac or iPhone configured to receive from anyone, without requiring any user interaction.
Additionally, a hidden authentication backdoor was identified in multiple firmware versions of Tenda routers. This flaw could grant an attacker administrative access to the device's web management panel. The CERT Coordination Center reported that the issue remains unaddressed as the manufacturer could not be reached.






