Skip to content
← All Threat Actors
Nation-State high China (PRC)

UAT-7810

China-nexus (Cisco Talos — assessed with high confidence as Chinese state-sponsored) · Infrastructure-as-a-service for Chinese cyber espionage — building and maintaining Operational Relay Box networks for client APT groups

Reports 1
Active Since 2024
Last Reported 9 Jul 2026
Sectors Targeted critical-infrastructure, communications, government, finance

Tactics, Techniques & Procedures (TTPs)

  • LONGLEASH backdoor: Go-based implant for SOHO router compromise, providing persistent remote access and proxy relay capability
  • DOGLEASH: second-stage payload providing interactive command execution, file staging, and credential collection from compromised routers
  • JARLEASH: tertiary implant for lateral movement and additional relay node provisioning within compromised networks
  • LapDogs campaign: systematic compromise of Ruckus and ASUS SOHO routers across residential and small business deployments globally
  • ORB network construction and management: compromised routers provisioned as operational relay boxes for downstream Chinese APT operators (UAT-5918 confirmed customer)
  • Division of labour model: UAT-7810 builds and maintains relay infrastructure; client groups (UAT-5918, others) conduct actual espionage operations through it
  • Residential and small business IP addresses as relay nodes: traffic appears to originate from legitimate users, defeating geographic blocking, reputation scoring, and attribution

Known Targets

SOHO router owners globally (Ruckus, ASUS — compromised as involuntary infrastructure nodes)Via UAT-5918 customer activity: government agencies, critical infrastructure operators, research institutions across Southeast Asia and beyond

Analyst Notes

Disclosed by Cisco Talos in July 2026. UAT-7810's role in the Chinese APT ecosystem is infrastructure specialisation: the group focuses exclusively on building and managing the Operational Relay Box networks that other Chinese state cyber actors use to route their operations through residential and small business IP addresses. This division of labour — separate teams for infrastructure and operations — is itself intelligence about how China's offensive cyber programme is structured. The LONGLEASH/DOGLEASH/JARLEASH malware family targets SOHO routers specifically because they sit outside enterprise security monitoring and rarely receive security updates. Connections through these nodes look like legitimate consumer internet traffic; geographic blocking fails because the nodes are in the target country; reputation scoring fails because they are legitimate ISP-assigned addresses. UAT-5918 is the confirmed primary customer for UAT-7810 relay access, with targeting of government, critical infrastructure, and research organisations documented.

Also Known As

UAT-7810 (Cisco Talos designation)LapDogs (campaign designation)