HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

UAT‑7810 Threat Actor Expands Operational Relay Box (ORB) Network, Elevating Supply‑Chain Risk

Cisco Talos identifies the China‑nexus group UAT‑7810 adding new Operational Relay Box nodes to boost its command‑and‑control reach. The activity underscores the need for continuous third‑party monitoring and audit‑ready evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 blog.talosintelligence.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
blog.talosintelligence.com

UAT‑7810 Threat Actor Expands Operational Relay Box (ORB) Network, Elevating Supply‑Chain Risk

What Happened — Cisco Talos reports that the China‑nexus threat group UAT‑7810 has been actively expanding its Operational Relay Box (ORB) infrastructure, adding new relay nodes to support command‑and‑control (C2) operations. The growth of the ORB network increases the group’s ability to pivot through compromised third‑party environments and exfiltrate data.

Why It Matters for Compliance & Audit Readiness

  • The ORB expansion is a classic supply‑chain attack vector; SOC 2 programs must demonstrate continuous monitoring of third‑party risk and the effectiveness of controls that detect anomalous network traffic.
  • Evidence of ongoing ORB activity can be captured as audit‑ready logs, satisfying the SOC 2 CC6.1 (Monitoring) and CC7.1 (System Operations) criteria.
  • Mapping this threat to your control framework helps prove due‑diligence to auditors and stakeholders.

Who Is Affected — Technology‑SaaS providers, cloud‑infrastructure operators, and any organization that relies on third‑party services for data processing or hosting.

Recommended Actions

  • Map the ORB threat to your existing SOC 2 controls (e.g., CC6.1 Monitoring, CC7.1 System Operations) and verify that logging, network segmentation, and anomaly detection are in place.
  • Integrate continuous threat‑intel feeds (such as Cisco Talos) into your security information and event management (SIEM) platform to generate audit‑ready evidence of detection and response.

Technical Notes — The ORB network is a modular C2 architecture that leverages compromised servers as relay points, enabling stealthy lateral movement. No specific CVE is cited; the threat is operational rather than vulnerability‑based. Source: Cisco Talos Threat Source newsletter

📰 Original Source
https://blog.talosintelligence.com/winning-54-of-the-time/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →