China‑Linked APT UAT‑7810 Expands ORB Network by Compromising Internet‑Facing Networking Devices
What Happened – The China‑state‑aligned threat group UAT‑7810 has been observed refining its custom “LapDogs” malware to infiltrate internet‑exposed routers, switches and other networking gear. By gaining footholds on these devices the actors are enlarging their Operational Relay Box (ORB) botnet, which can be used to relay traffic, stage lateral movement, or launch downstream attacks.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a classic control‑gap scenario that SOC 2 continuous‑compliance programs are built to detect and evidence – unauthorised access to critical infrastructure should be captured by change‑management and system‑operations controls.
- Mapping the compromised devices to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) and collecting continuous monitoring logs provides defensible audit evidence that the organization is exercising due diligence.
- Verisq’s Control Mapping capability can automatically correlate device‑level alerts with the relevant SOC 2 controls, creating a real‑time audit trail.
Who Is Affected – Telecommunications carriers, cloud‑infrastructure providers, large enterprises that expose routing/switching equipment to the internet, and any downstream customers that rely on those networks.
Recommended Actions
- Conduct an immediate inventory of all internet‑facing networking assets and verify they are covered by your change‑management and system‑operations controls.
- Map each asset to the appropriate SOC 2 control (CC6.1, CC7.1) and begin continuous log collection for configuration changes and access events.
- Deploy automated vulnerability scanning and patch management on the identified devices; prioritize any CVEs referenced in threat‑intel feeds.
- Integrate alerts from network‑security tools into your compliance dashboard to maintain a defensible audit trail.
Source: The Hacker News – China‑Linked UAT‑7810 Expands ORB Network With New LONGLEASH Malware
Technical Notes – The ORB network relies on the “LapDogs” malware family, which has been evolving since June 2025. The group exploits vulnerabilities in common router firmware (specific CVEs not disclosed) and leverages default or weak credentials to gain persistence. No direct data exfiltration was reported, but the compromised devices can serve as a launchpad for further attacks.