type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [c2, loader, web-shell] ยท confidence: medium ยท affected_sectors: [technology, defence] ยท au_impact: false
LONGLEASH
LONGLEASH is a malware strain actively developed and refined by China-linked APT actor Uat 7810. It is designed to compromise internet-facing networking devices and incorporate them into the LapDogs Operational Relay Box (ORB) proxy network.
Function
- Targeted at internet-facing networking devices (routers, firewalls, VPN gateways)
- Used to expand the LapDogs ORB infrastructure
- The ORB network is then leveraged by UAT-5918 for attacks on critical infrastructure in Taiwan (raw/digests/Cyber-Digest-2026-07-09)
Associated Infrastructure
- LapDogs ORB: An operational relay network built from compromised devices
- Downstream attacks on Taiwanese critical infrastructure by UAT-5918
Related Pages
- Uat 7810 โ The APT group developing this malware
- Modbeacon Rat โ Different RAT with modern C2 (gRPC)
- Netnut Takedown โ Contrast with residential proxy takedown