HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

China‑Linked APT UAT‑7810 Expands ORB Network by Compromising Internet‑Facing Networking Devices

UAT‑7810 has refined its LapDogs malware to infiltrate routers and switches exposed to the internet, enlarging its Operational Relay Box botnet. The incident highlights the need for SOC 2 control mapping and continuous evidence collection to prove due diligence on network‑infrastructure security.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

China‑Linked APT UAT‑7810 Expands ORB Network by Compromising Internet‑Facing Networking Devices

What Happened – The China‑state‑aligned threat group UAT‑7810 has been observed refining its custom “LapDogs” malware to infiltrate internet‑exposed routers, switches and other networking gear. By gaining footholds on these devices the actors are enlarging their Operational Relay Box (ORB) botnet, which can be used to relay traffic, stage lateral movement, or launch downstream attacks.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a classic control‑gap scenario that SOC 2 continuous‑compliance programs are built to detect and evidence – unauthorised access to critical infrastructure should be captured by change‑management and system‑operations controls.
  • Mapping the compromised devices to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) and collecting continuous monitoring logs provides defensible audit evidence that the organization is exercising due diligence.
  • Verisq’s Control Mapping capability can automatically correlate device‑level alerts with the relevant SOC 2 controls, creating a real‑time audit trail.

Who Is Affected – Telecommunications carriers, cloud‑infrastructure providers, large enterprises that expose routing/switching equipment to the internet, and any downstream customers that rely on those networks.

Recommended Actions

  • Conduct an immediate inventory of all internet‑facing networking assets and verify they are covered by your change‑management and system‑operations controls.
  • Map each asset to the appropriate SOC 2 control (CC6.1, CC7.1) and begin continuous log collection for configuration changes and access events.
  • Deploy automated vulnerability scanning and patch management on the identified devices; prioritize any CVEs referenced in threat‑intel feeds.
  • Integrate alerts from network‑security tools into your compliance dashboard to maintain a defensible audit trail.

Source: The Hacker News – China‑Linked UAT‑7810 Expands ORB Network With New LONGLEASH Malware

Technical Notes – The ORB network relies on the “LapDogs” malware family, which has been evolving since June 2025. The group exploits vulnerabilities in common router firmware (specific CVEs not disclosed) and leverages default or weak credentials to gain persistence. No direct data exfiltration was reported, but the compromised devices can serve as a launchpad for further attacks.

📰 Original Source
https://thehackernews.com/2026/07/china-linked-uat-7810-expands-orb.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →