APT UAT‑7810 Expands ORB Relay Networks with New Malware and Exploits Unpatched Ruckus Router Vulnerabilities
What Happened — Cisco Talos reports that the China‑nexus APT group UAT‑7810 has released two additional backdoor families (DOGLEASH and JARLEASH) and a newer version of its SHORTLEASH malware (“LONGLEASH”). The actors continue to host these payloads on fresh infrastructure and are actively exploiting known Ruckus wireless router CVEs (CVE‑2020‑22653, CVE‑2020‑22658, CVE‑2023‑25717) to seed their Operational Relay Box (ORB) network.
Why It Matters for Compliance & Audit Readiness
- The campaign illustrates a classic control‑gap scenario: unpatched network equipment providing a foothold for multi‑stage attacks.
- SOC 2‑aligned programs must map such gaps to the System Operations (CC6.1) and Change Management (CC6.2) criteria, continuously collect evidence of patch status, and retain audit‑ready logs.
- Verisq’s Control Mapping capability helps you automatically align discovered vulnerabilities to your control framework and generate continuous evidence for auditors.
Who Is Affected — Organizations that deploy Ruckus wireless routers or similar edge networking gear, across sectors such as technology, manufacturing, retail, and government.
Recommended Actions
- Inventory all Ruckus (and other vendor) wireless devices and verify firmware versions against the CVEs listed.
- Map the patch‑management process to SOC 2 CC6.1/CC6.2 controls; capture remediation tickets and patch‑verification logs as audit evidence.
- Deploy continuous monitoring to detect exploitation attempts on known router CVEs and integrate findings into your compliance dashboard.
Technical Notes — The new malware families are C‑based (DOGLEASH) and Java‑based (JARLEASH) backdoors capable of arbitrary shellcode execution, FTP/SFTP, and Netcat file transfers. Exploited CVEs affect Ruckus routers’ web‑interface authentication and command injection paths. Source: Cisco Talos Blog