HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Chinese Hackers Deploy LONGLEASH Malware to Expand ORB Relay Network Across Unpatched Ruckus and ASUS Routers

Cisco Talos uncovered LONGLEASH, a new backdoor used by the UAT‑7810 APT group to compromise unpatched Ruckus and ASUS routers, creating a proxy infrastructure that evades detection. The incident highlights the need for continuous device‑level control monitoring to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Chinese Hackers Deploy LONGLEASH Malware to Expand ORB Relay Network Across Unpatched Ruckus and ASUS Routers

What Happened — Researchers at Cisco Talos identified a new malware family, LONGLEASH, used by the China‑aligned APT group UAT‑7810 to compromise internet‑facing networking devices. The campaign leverages known vulnerabilities (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717 in Ruckus routers and CVE‑2025‑2492 in ASUS AiCloud routers) to build an Operational Relay Box (ORB) infrastructure that proxies traffic and hides attacker activity.

Why It Matters for Compliance & Audit Readiness

  • Unpatched network gear creates a control gap that defeats the SOC 2 Change Management and System Operations criteria; continuous evidence of patch status is essential.
  • The ORB relay architecture illustrates why organizations must map device‑level controls to a centralized audit trail—something Verisq’s Control Mapping capability can automate and continuously validate.
  • Demonstrating due‑diligence on third‑party hardware (vendor risk) and maintaining real‑time configuration evidence are key audit artifacts for SOC 2 readiness.

Who Is Affected — Telecommunications providers, ISPs, enterprises with on‑premise networking equipment, managed service providers, and any organization that relies on Ruckus or ASUS routers for internet access.

Recommended Actions

  • Conduct an inventory of all internet‑facing routers and IoT devices; cross‑reference with known CVE lists.
  • Implement a patch‑management process that logs each update as SOC 2 evidence (CC6.1).
  • Deploy continuous configuration monitoring to capture baseline and drift, feeding directly into your audit repository.
  • Map the identified control gaps to SOC 2 criteria and generate automated evidence for upcoming audits.

Source: BleepingComputer

Technical Notes

  • Attack vector: exploitation of unpatched firmware vulnerabilities (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717, CVE‑2025‑2492).
  • Malware capabilities: multi‑protocol proxying (HTTP, DNS, SOCKS, TCP, ICMP, UDP), TLS/PKI support, self‑removal, and intermediate C2 functions.
  • Data exposure: potential interception of internal traffic, credential theft, and lateral movement across compromised devices.
📰 Original Source
https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →