Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [apt-group, c2, loader] ยท confidence: medium ยท affected_sectors: [technology, government, defence, energy] ยท au_impact: false

UAT-7810

UAT-7810 is a China-linked advanced persistent threat (APT) actor tracked by Cisco Talos. The group is actively refining the Longleash malware to compromise internet-facing networking devices and expand the LapDogs Operational Relay Box (ORB) proxying infrastructure.

Activities

  • Develops and refines Longleash malware targeting networking devices
  • Builds and maintains the LapDogs ORB โ€” a network of compromised devices used as relay points
  • The ORB infrastructure is then leveraged by UAT-5918, another China-nexus actor, for attacks on critical infrastructure in Taiwan

Infrastructure

  • LapDogs ORB (Operational Relay Box): A proxy/relay network constructed from compromised internet-facing networking devices
  • Acts as an operational relay for downstream attacks by other threat actors

Related Pages

  • Longleash โ€” The malware tool used by this group
  • Silver Fox โ€” Another China-linked group
  • Netnut Takedown โ€” Comparison: residential proxy abuse vs. compromised device relay networks