Dormant Medium impact Espionage Checked 1w ago

China-linked group expands router-hijacking spy network

A China-linked hacking group tracked as UAT-7810 keeps growing a network of hijacked home and business routers it uses to hide cyberattacks, called LapDogs. Cisco Talos says the group has added new backdoor malware, including LongLeash, DogLeash and JarLeash, to compromise more unpatched Ruckus and ASUS AiCloud routers. The network was first found in 2025 and researchers say it was still being actively expanded as of July 2026.

Started
Jun 23, 2025
Latest activity
Jul 8, 2026
Attributed to
UAT-7810 (China-nexus)Likely
Where
United States
Sectors
Technology, Government
Scale
unknown number of hijacked home and business routers worldwide, mainly Ruckus wireless routers and ASUS AiCloud devices

Current status

As of September 4, 2026, no new credible reporting on UAT-7810 or the LapDogs router network has appeared since the July 8, 2026 Cisco Talos disclosure of the LongLeash, DogLeash and JarLeash backdoors.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Cisco Talos attributes the campaign to China-linked actor UAT-7810 with high confidence; no government has confirmed this.

Impact

Attackers are breaking into internet-facing routers and using them as hidden relay points to route and disguise other cyberattacks, rather than stealing data directly from the routers' owners.

What to do

If you run a Ruckus wireless router or an ASUS router with AiCloud enabled, install the latest firmware update and disable AiCloud remote access if you do not need it.

Timeline

  1. Aug 7, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 8, 2026

    Cisco Talos disclosed new LongLeash, DogLeash and JarLeash backdoors and noted the group also linked to ASUS AiCloud router exploitation via CVE-2025-2492.

    Activesecurityweek.com
  3. Jun 26, 2026

    Researchers reported UAT-7810 continuing to exploit unpatched Ruckus wireless routers to grow the network.

    Activecybersecuritynews.com
  4. Jun 23, 2025

    SecurityScorecard first disclosed the LapDogs ORB network of hijacked SOHO devices used to disguise Chinese state-linked attacks on US and Asian targets.

    Activeinfosecurity-magazine.com

Sources

Related reports