UAT-7810 is moving from using compromised routers for its own traffic to operating a reusable relay layer that other China-linked actors can borrow. Once an edge device is folded into that network, source IP, geolocation, and simple proxy blocking stop telling defenders who is really behind the intrusion.
Cisco Talos says the group is refining LONGLEASH and adding DOGLEASH, JARLEASH, and LeashTest to expand LapDogs across more hardware, including MIPS, ARM, and x64 systems. Talos links the activity to unpatched Ruckus router flaws CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and ASUS AiCloud CVE-2025-2492, and says UAT-7810 is providing relay infrastructure that UAT-5918 has already used against critical infrastructure targets.
The forward risk is shared infrastructure. Cleaning one router or blocking one relay does not remove the service layer if the device is still being used as a reusable ORB node for later espionage.