type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [apt-group, c2, loader] ยท confidence: medium ยท affected_sectors: [technology, government, defence, energy] ยท au_impact: false
UAT-7810
UAT-7810 is a China-linked advanced persistent threat (APT) actor tracked by Cisco Talos. The group is actively refining the Longleash malware to compromise internet-facing networking devices and expand the LapDogs Operational Relay Box (ORB) proxying infrastructure.
Activities
- Develops and refines Longleash malware targeting networking devices
- Builds and maintains the LapDogs ORB โ a network of compromised devices used as relay points
- The ORB infrastructure is then leveraged by UAT-5918, another China-nexus actor, for attacks on critical infrastructure in Taiwan
Infrastructure
- LapDogs ORB (Operational Relay Box): A proxy/relay network constructed from compromised internet-facing networking devices
- Acts as an operational relay for downstream attacks by other threat actors
Related Pages
- Longleash โ The malware tool used by this group
- Silver Fox โ Another China-linked group
- Netnut Takedown โ Comparison: residential proxy abuse vs. compromised device relay networks