Ghost Routes: How PRC-Nexus Actors Build ORB Networks to Disappear in Plain Sight
Consider a scenario: your firewall blocked a connection from a Vietnamese ISP. You logged it, flagged it, moved on. What you didn't see was that the actual operator sat in China, routing through a compromised ASUS router in Ho Chi Minh City as a stepping stone toward your network. That's the entire point. That's how Operational Relay Box (ORB) networks work. Cisco Talos published research tracking a group designated UAT-7810, assessed with high confidence to be a China-nexus actor responsible for maintaining and proliferating the "LapDogs" ORB network [1]. The group deploys updated and entirely new malware families across MIPS, ARM, and x64 architectures, targeting SOHO routers and network devices.
This isn't a static threat. UAT-7810 is most likely tasked with establishing ORB networks that secondary threat actors then use to conduct their own attacks against high-value targets [1]. The division of labor is deliberate: one group builds the plumbing, another group uses it for espionage.
What an ORB Network Actually Is
An Operational Relay Box network is a mesh of compromised or leased nodes used to proxy attacker traffic. Think of it as a VPN built from other people's hardware, without their knowledge.
These networks typically operate in two layers. The first layer consists of relay nodes: devices that accept incoming connections and forward them toward the target. The second layer consists of exit nodes that actually touch victim infrastructure. By chaining multiple hops together, the true source IP becomes nearly impossible to trace through standard forensic methods.
What separates ORB networks from simple proxy chains is scale and turnover. Mandiant's 2024 research identified ORB network operators managing networks comprising hundreds of thousands of nodes, with regular infrastructure rotation where IP addresses can be cycled in as few as 31 days to evade detection and complicate attribution [2]. The UAT-7810 relationship with downstream actors follows this same pattern. Talos tracks at least one secondary China-nexus APT, UAT-5918, that uses infrastructure provided by UAT-7810 [1].
The Actors: UAT-7810 and the LapDogs ORB
Cisco Talos is actively tracking UAT-7810 as the APT actor responsible for the LapDogs ORB network, first disclosed by SecurityScorecard in 2025 [1]. The group's operational focus is infrastructure construction, not direct espionage. Its purpose is to provide a covert communications backbone for other PRC-nexus groups.
Open-source reporting has shown overlapping tooling between UAT-5918 and UAT-7810, but Talos currently considers them separate APT actors with their own objectives and targets [1]. This organizational separation is a hallmark of mature PRC cyber operations. The builder group (UAT-7810) maintains persistent access on compromised devices and keeps the network healthy. The consumer groups (like UAT-5918) focus on intelligence collection against their assigned targets, using the ORB as an anonymization layer.
The Arsenal: LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST
UAT-7810's malware toolkit has expanded significantly. Talos tracks the following families:
SHORTLEASH was the original backdoor used by UAT-7810 to build the LapDogs ORB network [1]. It served as the foundation for the group's relay infrastructure.
LONGLEASH is an updated version of SHORTLEASH with enhanced capabilities including reverse shell and proxying functionality [1]. Talos tracks it as a distinct variant. The development of a companion testing utility called LEASHTEST suggests UAT-7810 is still testing LONGLEASH functionality and may not be fully confident of its behavior on MIPS devices [1]. This is a meaningful detail: it indicates the group is actively developing and debugging implants for embedded architectures commonly found in routers.
DOGLEASH is a new Linux backdoor written in C, discovered in UAT-7810's arsenal [1]. Its existence alongside LONGLEASH suggests the group maintains multiple implant options, likely to handle different target device architectures or to provide redundancy.
JARLEASH is a new administrative tool identified in UAT-7810's toolkit [1]. Its specific role within the group's operations alongside the backdoor families warrants further analysis as additional reporting becomes available.
The multi-architecture approach (MIPS, ARM, x64) combined with multi-language development reflects a group that is systematically expanding the types of devices it can compromise and convert into relay nodes.
The Low-Hanging Fruit: Edge Devices and SOHO Routers
PRC-nexus actors have clear preferences when building ORB infrastructure. UAT-7810 specifically targets Ruckus and ASUS routers, exploiting known vulnerabilities including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus devices, and CVE-2025-2492 in ASUS AiCloud-enabled devices [1].
Broader PRC-nexus ORB operations have historically also targeted:
- Other SOHO routers: TP-Link, Netgear, and MikroTik devices are known targets of various PRC-nexus ORB campaigns. Many run outdated firmware with known vulnerabilities and are rarely monitored by their owners.
- VPN appliances: While not specifically observed in UAT-7810 operations, Ivanti Connect Secure, Fortinet FortiGate, and Pulse Secure devices are known targets of other PRC-nexus actors and are plausible candidates for ORB infrastructure recruitment.
- Leased VPS instances: Servers from cloud providers in jurisdictions with minimal abuse reporting add legitimacy to attacker traffic [2].
- Residential broadband modems: Traffic from a residential IP in a non-adversary country looks like a human user, not an attacker.
The critical takeaway is that UAT-7810 is exploiting well-known, patched vulnerabilities in devices that simply never received updates [1]. No EDR agent. No SIEM integration. No security team monitoring its logs. A perfect relay.
IOC Table
| Type | Value | Context |
|---|---|---|
| Malware | SHORTLEASH | Original backdoor for LapDogs ORB network [1] |
| Malware | LONGLEASH | Updated version of SHORTLEASH with reverse shell and proxying capabilities [1] |
| Malware | DOGLEASH | Linux backdoor (C-based) in UAT-7810 arsenal [1] |
| Malware | JARLEASH | Administrative tool in UAT-7810 arsenal [1] |
| Malware | LEASHTEST | Testing utility for LONGLEASH on MIPS devices [1] |
| CVE | CVE-2020-22653 | Ruckus router vulnerability exploited by UAT-7810 [1] |
| CVE | CVE-2020-22658 | Ruckus router vulnerability exploited by UAT-7810 [1] |
| CVE | CVE-2023-25717 | Ruckus router vulnerability exploited by UAT-7810 [1] |
| CVE | CVE-2025-2492 | ASUS AiCloud vulnerability exploited by UAT-7810 [1] |
| Detection | Snort SIDs 66430, 66431, 66432, 66433, 301493 | Talos-published detection signatures for UAT-7810 malware families [1] |
Note: Talos published Snort SIDs and ClamAV signatures for detection of UAT-7810 malware families. Specific network-level IOCs (IP addresses, domains) rotate frequently due to the nature of ORB infrastructure and have limited shelf life. Defenders should monitor Talos and SecurityScorecard advisories for updated network-level indicators.
MITRE ATT&CK Mapping
| Technique ID | Name | Context |
|---|---|---|
| T1584 | Compromise Infrastructure | UAT-7810 compromises SOHO routers and edge devices to build the LapDogs relay network [1] |
| T1090.003 | Proxy: Multi-hop Proxy | ORB networks chain multiple compromised nodes to obscure true source IPs [1][2] |
| T1587.001 | Develop Capabilities: Malware | Development of LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST across multiple architectures [1] |
| T1190 | Exploit Public-Facing Application | UAT-7810 exploits known vulnerabilities (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492) in internet-facing routers [1] |
Detection and Hunting
ORB networks are deliberately designed to frustrate traditional IOC-based detection. Blocking a single IP address does nothing when the operator can rotate to a different compromised node within hours. Defenders need to focus on behavioral indicators and anomaly detection.
Network-Level Anomalies
Look for outbound connections from your environment to SOHO router management interfaces (ports 8443, 443, 8080) on residential IP ranges. These shouldn't be common in enterprise traffic. Similarly, hunt for inbound connections from residential ISP ranges that exhibit patterns inconsistent with normal user behavior: connections at unusual hours, consistent timing intervals, or connections to sensitive internal systems.
Signature-Based Detection
Deploy Talos-published Snort signatures (SIDs 66430, 66431, 66432, 66433, 301493) covering LONGLEASH, DOGLEASH, JARLEASH, and architecture-specific variants. Deploy ClamAV signatures published by Talos for file-level detection of UAT-7810 malware families.
DNS and Traffic Analysis
Monitor for DNS queries from network segments that shouldn't be making external DNS requests. Anomalous outbound connections from network appliances or embedded devices warrant investigation.
Edge Device Integrity
For organizations managing their own SOHO or branch office routers, implement firmware integrity checking on a scheduled basis. Any router running firmware older than its last known security update is a candidate for compromise. Pay particular attention to Ruckus and ASUS devices given confirmed UAT-7810 targeting, as well as TP-Link and MikroTik devices targeted by other PRC-nexus ORB operations.
Sigma Rule: Suspicious Outbound Connection to Residential IP Range
title: Outbound Connection to Residential ISP Range on Router Management Port
id: a3f8e2c1-9b47-4d5e-8f12-7c3a6b9d0e54
status: experimental
author: RedSheepSec
date: 2026/09/04
description: Detects outbound connections to common SOHO router management ports on residential IP ranges, which may indicate ORB network communication.
logsource:
category: firewall
detection:
selection:
dst_port:
- 8443
- 8080
- 443
action: allowed
filter:
dst_ip|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection and not filter
falsepositives:
- Legitimate remote administration of branch office equipment
- VPN connections to home offices
level: low
tags:
- attack.command_and_control
- attack.t1090.003
This rule is intentionally broad. It needs tuning against your environment's baseline, but it provides a starting point for identifying ORB-style relay traffic.
Analysis
The UAT-7810 operation represents a mature, industrialized approach to cyber infrastructure. By separating the infrastructure builders from the espionage operators, PRC-nexus groups achieve several strategic advantages.
First, compartmentalization. Burning one espionage operation doesn't burn the relay network, and the reverse also holds. Second, scalability. A dedicated team focused solely on compromising edge devices and maintaining implants can build infrastructure far faster than a team splitting its time between access operations and intelligence collection. Third, attribution resistance. When the exit node is a compromised ASUS router in Vietnam and the relay node is a VPS in Romania, connecting the activity to a specific Chinese intelligence service becomes extremely difficult.
The multi-architecture approach to malware development (MIPS and ARM for routers, x64 for servers) shows systematic engineering. The existence of LEASHTEST as a dedicated QA tool for MIPS implants is particularly telling [1]. This is a software development operation with testing pipelines, not an ad hoc hacking crew.
Red Sheep Assessment
Confidence: Moderate
The sources collectively paint a picture of a disciplined infrastructure-building operation. UAT-7810's development of multiple malware families across different architectures and languages suggests the group is preparing to expand beyond its current target set of Ruckus and ASUS routers.
The LEASHTEST utility is significant. Groups that build dedicated testing tools for their malware are not running short-term operations. They're building persistent infrastructure they expect to maintain and iterate on for years. The fact that LEASHTEST specifically targets MIPS behavior testing [1] indicates the group encountered reliability problems with their implants on embedded devices and responded with engineering discipline rather than abandoning the platform.
There is a contrarian interpretation worth considering: the separation between UAT-7810 and UAT-5918 might be organizational rather than operational. Talos currently treats them as distinct actors [1], but the overlapping tooling could indicate a single organization with different internal teams rather than truly independent groups. This distinction matters for threat modeling. Separate organizations imply a service-provider model where ORB access might be shared across multiple Chinese intelligence consumers. A single organization with internal specialization implies tighter operational security but narrower usage.
Regardless of the organizational model, defenders face the same practical challenge: the traffic hitting their perimeter looks like it's coming from a legitimate device in a non-threatening country, and the underlying infrastructure will rotate before most threat intel feeds can blocklist it.
Defender's Checklist
- ▢[ ] Verify patches for CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 on all Ruckus routers, and CVE-2025-2492 on ASUS AiCloud-enabled devices. These are actively exploited by UAT-7810.
- ▢[ ] Deploy Snort SIDs 66430, 66431, 66432, 66433, and 301493 published by Cisco Talos for detection of UAT-7810 malware families. Deploy associated ClamAV signatures.
- ▢[ ] Audit all internet-facing SOHO routers, VPN appliances, and NAS devices for firmware currency. Prioritize Ruckus and ASUS devices (confirmed UAT-7810 targets), then TP-Link and MikroTik devices.
- ▢[ ] Implement network flow analysis to baseline normal traffic patterns from branch offices and remote sites. Flag connections to residential IP ranges on management ports (8443, 8080) for review.
- ▢[ ] Hunt for unexpected processes on network appliances, NAS devices, and non-workstation endpoints. ORB implants will leave artifacts on compromised devices.
- ▢[ ] Review firewall logs for outbound connections from DMZ or edge devices to external IPs that don't match expected update or management destinations. ORB relay traffic will appear as device-to-device communication.
- ▢[ ] Subscribe to Cisco Talos and SecurityScorecard advisories for updated IOCs related to UAT-7810 and the LapDogs ORB network. IOC-based blocking has limited shelf life against ORB infrastructure, but it catches delayed rotations.
References
- Cisco Talos, "UAT-7810 continues building ORB networks using new malware," https://blog.talosintelligence.com/uat-7810/
- Mandiant, "Unmasking the ORB Networks," https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks