China-linked group expands router-hijacking spy network
A China-linked hacking group tracked as UAT-7810 keeps growing a network of hijacked home and business routers it uses to hide cyberattacks, called LapDogs. Cisco Talos says the group has added new backdoor malware, including LongLeash, DogLeash and JarLeash, to compromise more unpatched Ruckus and ASUS AiCloud routers. The network was first found in 2025 and researchers say it was still being actively expanded as of July 2026.
- Started
- Jun 23, 2025
- Latest activity
- Jul 8, 2026
- Attributed to
- UAT-7810 (China-nexus)Likely
- Where
- United States
- Sectors
- Technology, Government
- Scale
- unknown number of hijacked home and business routers worldwide, mainly Ruckus wireless routers and ASUS AiCloud devices
Current status
As of September 4, 2026, no new credible reporting on UAT-7810 or the LapDogs router network has appeared since the July 8, 2026 Cisco Talos disclosure of the LongLeash, DogLeash and JarLeash backdoors.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Cisco Talos attributes the campaign to China-linked actor UAT-7810 with high confidence; no government has confirmed this.
Impact
Attackers are breaking into internet-facing routers and using them as hidden relay points to route and disguise other cyberattacks, rather than stealing data directly from the routers' owners.
What to do
If you run a Ruckus wireless router or an ASUS router with AiCloud enabled, install the latest firmware update and disable AiCloud remote access if you do not need it.
Timeline
-
Aug 7, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 8, 2026
Cisco Talos disclosed new LongLeash, DogLeash and JarLeash backdoors and noted the group also linked to ASUS AiCloud router exploitation via CVE-2025-2492.
Activesecurityweek.com -
Jun 26, 2026
Researchers reported UAT-7810 continuing to exploit unpatched Ruckus wireless routers to grow the network.
Activecybersecuritynews.com -
Jun 23, 2025
SecurityScorecard first disclosed the LapDogs ORB network of hijacked SOHO devices used to disguise Chinese state-linked attacks on US and Asian targets.
Activeinfosecurity-magazine.com
Sources
- China-Linked APT Expands Arsenal With New 'Leash' Backdoors SecurityWeek Jul 8, 2026
- China-linked attackers add new malware to hijack routers TheHackerNews Jul 8, 2026
- China-linked attackers add new malware to their proxy network Infosecurity Magazine Jul 8, 2026
- China attackers hijack Ruckus routers to hide attacks Cyber Security News Jun 26, 2026
- Chinese hackers develop LONGLEASH malware to expand ORB network Bleeping Computer Jul 7, 2026
Related reports
- China-linked attackers add new malware to their proxy network Jul 8, 2026
- China-linked group hijacks routers for spy relay network Jul 8, 2026
- China-linked attackers build spy networks with new malware Jul 7, 2026
- China-linked attackers add new router malware Jul 3, 2026
- China attackers hijack Ruckus routers to hide attacks Jun 26, 2026