Chinese Hackers Deploy LONGLEASH Malware to Expand ORB Relay Network Across Unpatched Ruckus and ASUS Routers
What Happened — Researchers at Cisco Talos identified a new malware family, LONGLEASH, used by the China‑aligned APT group UAT‑7810 to compromise internet‑facing networking devices. The campaign leverages known vulnerabilities (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717 in Ruckus routers and CVE‑2025‑2492 in ASUS AiCloud routers) to build an Operational Relay Box (ORB) infrastructure that proxies traffic and hides attacker activity.
Why It Matters for Compliance & Audit Readiness
- Unpatched network gear creates a control gap that defeats the SOC 2 Change Management and System Operations criteria; continuous evidence of patch status is essential.
- The ORB relay architecture illustrates why organizations must map device‑level controls to a centralized audit trail—something Verisq’s Control Mapping capability can automate and continuously validate.
- Demonstrating due‑diligence on third‑party hardware (vendor risk) and maintaining real‑time configuration evidence are key audit artifacts for SOC 2 readiness.
Who Is Affected — Telecommunications providers, ISPs, enterprises with on‑premise networking equipment, managed service providers, and any organization that relies on Ruckus or ASUS routers for internet access.
Recommended Actions
- Conduct an inventory of all internet‑facing routers and IoT devices; cross‑reference with known CVE lists.
- Implement a patch‑management process that logs each update as SOC 2 evidence (CC6.1).
- Deploy continuous configuration monitoring to capture baseline and drift, feeding directly into your audit repository.
- Map the identified control gaps to SOC 2 criteria and generate automated evidence for upcoming audits.
Source: BleepingComputer
Technical Notes
- Attack vector: exploitation of unpatched firmware vulnerabilities (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717, CVE‑2025‑2492).
- Malware capabilities: multi‑protocol proxying (HTTP, DNS, SOCKS, TCP, ICMP, UDP), TLS/PKI support, self‑removal, and intermediate C2 functions.
- Data exposure: potential interception of internal traffic, credential theft, and lateral movement across compromised devices.