2026-07-08NOTABLETalos: China-nexus UAT-7810 builds ORB relay networks from unpatched Ruckus/ASUS routers for secondary APTs
UAT-5918
actor · actor:uat-5918 single-source
China-nexus APT previously documented by Cisco Talos targeting critical infrastructure in Taiwan; named (Talos, 2026-07-07) as a secondary consumer of UAT-7810's ORB relay-network infrastructure.
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Talos: China-nexus UAT-7810 builds ORB relay networks from unpatched Ruckus/ASUS routers for secondary APTs
Peak priority
notable
1 notable
Targets
telco
sectors: telco, public-sector · regions: apac
Sources cited
1
1 hosts
Action items (2)
Do-now tasks recorded on the entries about UAT-5918, newest first. Check the date before acting on an older one.
- Patch or retire EoL Ruckus wireless APs and ASUS AiCloud routers exposed to CVE-2020-22653/-22658, CVE-2023-25717 and CVE-2025-2492; disable unneeded remote-management interfaces on edge/CPE devices.2026-07-08Talos: China-nexus UAT-7810 builds ORB relay…
- Baseline and alert on multi-protocol relay/fan-out behaviour (simultaneous HTTP/DNS/SOCKS/TCP/ICMP/UDP) from a single consumer-grade router or AP; treat inbound connections from residential/SOHO ranges into VPN/remote-access portals as a stronger signal than IP reputation alone.2026-07-08Talos: China-nexus UAT-7810 builds ORB relay…
Defender insights
What each entry about UAT-5918 tells a defender to do, newest first.
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- UAT-7810Talos: UAT-5918 consumes UAT-7810's ORB relay-network infrastructure
Story timeline
Hunting pivots
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- StealthIndicator Removal
- Command and ControlProxy: Multi-hop Proxy
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗
Command and Control TA0011
T1090.003Proxy: Multi-hop Proxy×1
Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.
Evidence: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗
Entries about UAT-5918 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- blog.talosintelligence.com1 (100%)