LONGLEASH Malware / UAT-7810 ORB Network Expansion
First seen Jul 8, 2026 · Updated Jul 8, 2026
Chinese state-linked threat actor UAT-7810 is deploying new malware dubbed LONGLEASH to expand an Operational Relay Box (ORB) network, primarily by compromising unpatched internet-facing Ruckus routers. The ORB network is used to anonymize and relay malicious traffic, complicating attribution and enabling downstream intrusion campaigns.
Technical Analysis
UAT-7810 is exploiting unpatched vulnerabilities in internet-facing Ruckus networking devices to gain footholds and deploy LONGLEASH, a malware implant that converts compromised routers into relay nodes within an ORB (Operational Relay Box) network. ORB networks function similarly to proxy botnets, allowing threat actors to route command-and-control and exfiltration traffic through legitimate-looking infrastructure, evading IP-based detection and geofencing controls. The campaign relies on unpatched edge devices as the initial access vector rather than software supply-chain compromise, and specific CVE details for the Ruckus vulnerabilities have not yet been disclosed in the source reporting. Organizations running AI agent infrastructure behind or adjacent to compromised edge routers face indirect risk: if agent hosts, API gateways, or RAG pipeline endpoints traverse networks relayed through this ORB, attackers could intercept, redirect, or man-in-the-middle traffic carrying API keys, model credentials, or tool-call data, warranting network segmentation review for any agent-serving infrastructure sitting behind unpatched Ruckus gear.
Affected Systems
Unpatched internet-facing Ruckus routers/networking devices; potentially other edge/perimeter devices incorporated into the ORB relay chain
Indicators of Compromise
- LONGLEASH malware implant (specific hashes not disclosed in source)
- Compromised Ruckus router endpoints (IPs not disclosed in source)
- ORB relay network infrastructure associated with UAT-7810
Remediation Steps
- 1
Patch and update Ruckus devices
Apply all available firmware updates and vendor security patches to Ruckus routers and networking equipment; if patches are unavailable, isolate or replace affected devices.
- 2
Restrict internet exposure
Remove unnecessary internet-facing management interfaces on routers and networking gear; enforce VPN or allow-listed access for administration.
- 3
Network traffic monitoring
Monitor for anomalous relay traffic patterns, unexpected outbound connections, or proxy-like behavior from edge devices consistent with ORB network activity.
- 4
Segment agent and API infrastructure
Ensure AI agent hosts, LLM API gateways, and RAG pipeline components are network-segmented from consumer/edge networking gear to reduce exposure to ORB relay traffic interception.
- 5
Credential rotation
Rotate API keys and credentials used by any systems whose traffic may have transited compromised or suspect network paths.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.