ctipilot.ch

LONGLEASH / SHORTLEASH ORB malware suite

tool · tool:longleash-orb-malware-suite single-source

UAT-7810's ORB-network malware suite (internally 'ff-agent'): LONGLEASH (enhanced SHORTLEASH successor, multi-protocol HTTP/DNS/SOCKS/TCP/ICMP/UDP proxying), DOGLEASH (C-based Linux backdoor), JARLEASH (Java admin/relay tool) and LEASHTEST; built with Boost.Asio, custom protobuf and MbedTLS, compiled MIPS/ARM/x64 (Cisco Talos, 2026-07-07).

Aliases: ff-agent, DOGLEASH, JARLEASH, LEASHTEST

Coverage timeline
2
first 2026-07-08 → last 2026-07-12
Peak priority
notable
2 notable
Sources cited
4
4 hosts
Sections touched
2
active-threats, weekly-research
Co-occurring entities
2
see Related entities below
ATT&CK techniques
5
pinned v19.2 · see below
2026-07-082 appearances2026-07-12

ATT&CK techniques

5 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-12/weekly-w28-threat-actor-developments · 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-12/weekly-w28-threat-actor-developments · ATT&CK page ↗

Stealth TA0005

T1070Indicator Removal×1

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Evidence: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-07-12/weekly-w28-threat-actor-developments · ATT&CK page ↗

Command and Control TA0011

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · ATT&CK page ↗

Story timeline

  1. 2026-07-12Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances
    weekly-researchActor developments this week — Group-IB recasts Scattered Spider as a decentralised collective; China/Iran edge, ORB and C2 tradecraft advance
  2. 2026-07-08Cisco Talos: China-nexus UAT-7810 expands its ORB network with LONGLEASH/DOGLEASH/JARLEASH via unpatched Ruckus and ASUS routers
    active-threatsTalos: China-nexus UAT-7810 builds ORB relay networks from unpatched Ruckus/ASUS routers for secondary APTs

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

used by

Where this entity is cited

  • active-threats1
  • weekly-research1

Source distribution

  • blog.talosintelligence.com1 (25%)
  • group-ib.com1 (25%)
  • proofpoint.com1 (25%)
  • research.checkpoint.com1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about LONGLEASH / SHORTLEASH ORB malware suite (2)

2026-07-12 · view entry permalink →

NOTABLENATOB2

Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances

The week's actor reporting split between a model-changing reframing of a well-known financially-motivated collective and a set of state-nexus tradecraft advances.

Scattered Spider — a model change, not an incident. Group-IB argues the actor "cannot be considered or analyzed as a single organized 'group' with its own hierarchy or organigram [but is] more accurately described as a decentralised cybercrime collective" of independent subclusters, typically 3-5 people, unified by shared tradecraft and community learning rather than command structure, and states "we can consider 0ktapus as a subcluster of Scattered Spider" — explicitly mapping Microsoft's Octo Tempest, Mandiant's UNC3944 and Palo Alto's Muddled Libra as overlapping labels for subclusters of the same movement (Group-IB, 2026-07-07). The documented playbook is squarely relevant to the constituency's help desks: vishing/smishing with Okta/Microsoft/Citrix/Google SSO-lookalike pages staged minutes before a call, SIM-swaps via coercion or carrier-staff social engineering, and help-desk impersonation using OSINT from already-compromised systems, monetised through BlackCat/ALPHV and DragonForce ransomware. The practical consequence Group-IB draws: because resilience comes from decentralisation, individual arrests do not blunt the collective, so defenders should treat each attributed intrusion as one small ad-hoc crew rather than evidence of a persistent central adversary.

State-nexus edge and C2 tradecraft. Talos detailed China-nexus UAT-7810 expanding its operational relay-box (ORB) network with the LONGLEASH/DOGLEASH/JARLEASH suite (Cisco Talos, 2026-07-08); Proofpoint's UNK_MassTraction, a suspected China-aligned actor, exploited Roundcube webmail as an edge device (Proofpoint, 2026-07-09); and Check Point exposed Iran MOIS-linked Cavern Manticore's modular .NET command-and-control framework with layered anti-analysis (Check Point Research, 2026-07-09).

Why grouped here: these are actor-model and capability developments — the lens the weekly owns — rather than new operational incidents. Scattered Spider's decentralisation and the state actors' edge/ORB focus both change how a SOC should scope attribution and where to look (help-desk identity workflows; internet-facing webmail and edge appliances as relay infrastructure).

Scattered Spider cannot be considered or analyzed as a single organized 'group' with its own hierarchy or organigram. Instead, it can be more accurately described as a decentralised cybercrime collective.

we can consider 0ktapus as a subcluster of Scattered Spider

Group-IB

Builds on: 2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash · 2026-07-09/unk-masstraction-roundcube-edge-exploitation · 2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis

research12 Jul 23:43Zsingle-sourceOpen finding ↗

2026-07-08 · view entry permalink →

NOTABLENATOB2

Cisco Talos: China-nexus UAT-7810 expands its ORB network with LONGLEASH/DOGLEASH/JARLEASH via unpatched Ruckus and ASUS routers

Cisco Talos profiled UAT-7810, a China-nexus actor Talos assesses with high confidence is tasked with building and maintaining Operational Relay Box (ORB) networks — relay/proxy infrastructure built from compromised networking gear that secondary China-nexus APTs use to launder the origin of operations against high-value targets (Cisco Talos, 2026-07-07). Talos names UAT-5918 — previously documented targeting Taiwanese critical infrastructure — as one such downstream consumer. Initial access is exploitation of known, unpatched vulnerabilities in Ruckus wireless routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492), a tactic UAT-7810 has used since 2025 rather than a fresh zero-day (T1190). The malware suite, internally "ff-agent", now includes LONGLEASH — an enhanced successor to the SHORTLEASH backdoor adding reverse-shell and HTTP/DNS/SOCKS/TCP/ICMP/UDP multi-protocol proxying (T1090.003) — plus DOGLEASH, a passive C-based Linux backdoor, and JARLEASH, a Java-based admin tool for file management and FTP/SFTP access; it is built with Boost.Asio, custom protobuf encoding and MbedTLS TLS proxying, compiled for MIPS/ARM/x64, and self-deletes if tampering or a suspicious connection is detected (T1070).

Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918.

Talos has observed UAT-7810 primarily exploit known vulnerabilities in unpatched Ruckus wireless routers, a tactic UAT-7810 has used since 2025.

Cisco Talos 2026-07-07
threat08 Jul 20:35Zsingle-sourceOpen finding ↗
Sources: Cisco Talos