HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

APT UAT‑7810 Expands ORB Relay Networks with New Malware and Exploits Unpatched Ruckus Router Vulnerabilities

Cisco Talos tracks APT UAT‑7810 releasing new backdoors (DOGLEASH, JARLEASH) and a newer SHORTLEASH variant while exploiting unpatched Ruckus router CVEs. The activity highlights a control‑gap scenario that SOC 2‑ready organizations must map, monitor, and evidence for audit readiness.

LiveThreat™ Intelligence · 📅 July 07, 2026· 📰 blog.talosintelligence.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
blog.talosintelligence.com

APT UAT‑7810 Expands ORB Relay Networks with New Malware and Exploits Unpatched Ruckus Router Vulnerabilities

What Happened — Cisco Talos reports that the China‑nexus APT group UAT‑7810 has released two additional backdoor families (DOGLEASH and JARLEASH) and a newer version of its SHORTLEASH malware (“LONGLEASH”). The actors continue to host these payloads on fresh infrastructure and are actively exploiting known Ruckus wireless router CVEs (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717) to seed their Operational Relay Box (ORB) network.

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates a classic control‑gap scenario: unpatched network equipment providing a foothold for multi‑stage attacks.
  • SOC 2‑aligned programs must map such gaps to the System Operations (CC6.1) and Change Management (CC6.2) criteria, continuously collect evidence of patch status, and retain audit‑ready logs.
  • Verisq’s Control Mapping capability helps you automatically align discovered vulnerabilities to your control framework and generate continuous evidence for auditors.

Who Is Affected — Organizations that deploy Ruckus wireless routers or similar edge networking gear, across sectors such as technology, manufacturing, retail, and government.

Recommended Actions

  • Inventory all Ruckus (and other vendor) wireless devices and verify firmware versions against the CVEs listed.
  • Map the patch‑management process to SOC 2 CC6.1/CC6.2 controls; capture remediation tickets and patch‑verification logs as audit evidence.
  • Deploy continuous monitoring to detect exploitation attempts on known router CVEs and integrate findings into your compliance dashboard.

Technical Notes — The new malware families are C‑based (DOGLEASH) and Java‑based (JARLEASH) backdoors capable of arbitrary shellcode execution, FTP/SFTP, and Netcat file transfers. Exploited CVEs affect Ruckus routers’ web‑interface authentication and command injection paths. Source: Cisco Talos Blog

📰 Original Source
https://blog.talosintelligence.com/uat-7810/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →