New research into the activities of the China-nexus threat group known as UAT-7810 shows an ongoing campaign to expand their operational relay box (ORB) network infrastructure. The group develops its own tooling, and Cisco Talos recently analyzed a newer version of the group’s SHORTLEASH backdoor that the researchers named LONGLEASH.

This threat actor, which has been active since at least 2025, functions primarily to establish and maintain relay networks that secondary China-nexus APT groups, such as UAT-5918, leverage for malicious operations against high-value targets. In this way, UAT-7810 functions as an initial access team.

The investigation into UAT-7810 shows significant evolution in their toolkit, specifically the development of a successor to their previously documented SHORTLEASH backdoor. This new iteration, known as LONGLEASH, represents a continued commitment to developing custom-made malware hosted on attacker-controlled infrastructure. SHORTLEASH provided robust functionality, including C2 communication, web server hosting, tunnel management, and acting as both a C2 server and client.

Beyond the update to their primary backdoor, Talos uncovered two additional malware families integrated into the UAT-7810 arsenal. The first, DOGLEASH, is a C-based backdoor capable of executing arbitrary shellcode on compromised Linux devices. DOGLEASH is deployed via shell scripts on compromised systems, where it binds to and listens on a specific port after iptables rules are modified to allow incoming TCP traffic. 

“Any TCP data received is then decoded using a hardcoded password string. Based on the command code and accompanying data received, it creates a new thread in the process and carries out a specific action,” the Talos researchers said.

This expansion of tools and infrastructure confirms UAT-7810’s role as a high level provider of relay capabilities for larger state-aligned cyber espionage operations.

The second new discovery is JARLEASH, a Java-based backdoor designed for administrative tasks such as file management, FTP, SFTP, and Netcat functionality. The tool is deployed both on the threat actor's own infrastructure and on compromised systems where a Java environment is present.

“Talos discovered four new servers being used by UAT-7810 to host malicious payloads for a variety of hardware platforms including MIPS, ARM, and x64. The malware hosted predominantly consists of DOGLEASH, and accompanying shell scripts are executed on compromised systems to download and execute DOGLEASH,” the researchers wrote.

Talos also identified a benign tool called LEASHTEST, an ELF binary used to test core functionality on MIPS-based embedded platforms. Its presence on a device should be seen as a high-confidence IoC by UAT-7810.

The operational methodology of UAT-7810 remains focused on the exploitation of n-day vulnerabilities, with a consistent preference for unpatched Ruckus wireless routers. Once a device is compromised, the actor employs a range of infrastructure—including at least four recently identified servers—to distribute payloads across diverse architectures, including MIPS, ARM, and x64. 

The actor’s executor utility continues to facilitate a broad suite of capabilities, such as reverse shells, packet redirection for various protocols including HTTP, DNS, SOCKS, TCP, ICMP, and UDP, and acting as an SMTP server and client. This expansion of tools and infrastructure confirms UAT-7810’s role as a high level provider of relay capabilities for larger state-aligned cyber espionage operations.