
A China‑linked hacking group tracked as UAT‑7810 has expanded its network of compromised routers, adding new malware implants to grow an operational relay box (ORB) used for espionage according to Cisco Talos. The activity, first seen in early July 2026, targets unpatched Ruckus and ASUS devices to create proxy nodes for covert command‑and‑control traffic as reported by securityonline.info.
Researchers from Cisco Talos identified three new implants dubbed LONGLEASH, DOGLEASH and JARLEASH that are being deployed on the affected hardware according to securityweek.com. These implants do not rely on a newly disclosed CVE but instead exploit known vulnerabilities in the router firmware to gain a foothold. Once installed they give the attackers the ability to route traffic through the device and to maintain a persistent command‑and‑control channel as noted by Infosecurity Magazine.
Telemetry from the group shows that more than one thousand small office and home office routers have been infected with variants of the Leash family as reported by The Hacker News. The latest LongLeash variant includes capabilities for hosting malicious payloads and for handling complex command‑and‑control interactions. The malware works in tandem with another China‑linked cluster tracked as UAT‑5918, suggesting a broader sharing of tools.
UAT‑7810 has been monitored by threat intelligence teams since 2025, yet no public arrests have been linked to the campaign according to Talos. The group’s infrastructure relies on a rotating set of servers and IP addresses hosted in various regions to store and deliver its payloads. This continual development of new backdoors indicates that the operation is still expanding and adapting to defences.
Network administrators should ensure that all Ruckus and ASUS routers are running the latest firmware versions supplied by the vendors as advised by Cisco Talos. Where remote administration is not required, those services should be disabled to reduce the attack surface. Traffic monitoring should focus on outbound connections to unfamiliar destinations, especially those that match the IP ranges associated with the Leash implants.
Maintaining an up‑to‑date inventory of edge devices helps identify any unmanaged hardware that might be missing patches as suggested by Infosecurity Magazine. Deploying intrusion detection or network behaviour analysis tools can flag the characteristic patterns of the Leash family, such as unusual DNS queries or unexpected port usage. Sharing indicators of compromise with trusted peers and feeding them into threat intelligence platforms improves the chance of catching the activity early.