UAT-7810
China-nexus (Cisco Talos — assessed with high confidence as Chinese state-sponsored) · Infrastructure-as-a-service for Chinese cyber espionage — building and maintaining Operational Relay Box networks for client APT groups
Tactics, Techniques & Procedures (TTPs)
- LONGLEASH backdoor: Go-based implant for SOHO router compromise, providing persistent remote access and proxy relay capability
- DOGLEASH: second-stage payload providing interactive command execution, file staging, and credential collection from compromised routers
- JARLEASH: tertiary implant for lateral movement and additional relay node provisioning within compromised networks
- LapDogs campaign: systematic compromise of Ruckus and ASUS SOHO routers across residential and small business deployments globally
- ORB network construction and management: compromised routers provisioned as operational relay boxes for downstream Chinese APT operators (UAT-5918 confirmed customer)
- Division of labour model: UAT-7810 builds and maintains relay infrastructure; client groups (UAT-5918, others) conduct actual espionage operations through it
- Residential and small business IP addresses as relay nodes: traffic appears to originate from legitimate users, defeating geographic blocking, reputation scoring, and attribution
Known Targets
Analyst Notes
Disclosed by Cisco Talos in July 2026. UAT-7810's role in the Chinese APT ecosystem is infrastructure specialisation: the group focuses exclusively on building and managing the Operational Relay Box networks that other Chinese state cyber actors use to route their operations through residential and small business IP addresses. This division of labour — separate teams for infrastructure and operations — is itself intelligence about how China's offensive cyber programme is structured. The LONGLEASH/DOGLEASH/JARLEASH malware family targets SOHO routers specifically because they sit outside enterprise security monitoring and rarely receive security updates. Connections through these nodes look like legitimate consumer internet traffic; geographic blocking fails because the nodes are in the target country; reputation scoring fails because they are legitimate ISP-assigned addresses. UAT-5918 is the confirmed primary customer for UAT-7810 relay access, with targeting of government, critical infrastructure, and research organisations documented.
Also Known As
MITRE ATT&CK Techniques