Chinese hackers develop LONGLEASH malware to expand ORB network

Discover how the UAT-7810 group uses LONGLEASH malware to compromise Ruckus routers and expand its ORB network. Learn about the protection measures.

miércoles, 8 de julio de 2026 • 2 min read • Q2BSTUDIO Team

Expanding the ORB network through vulnerable routers

In the current cyber threat landscape, state-sponsored groups continue to refine their tactics to infiltrate critical infrastructures. Recently, a group of Chinese attackers, tracked as UAT-7810, has been actively evolving its malware known as LONGLEASH. This malicious software is designed to expand a network of operational relay boxes (ORB) by compromising internet-exposed network devices, especially Ruckus routers lacking security patches. The strategy is not new, but the sophistication of the malware and its persistence capabilities represent a growing challenge for organizations that rely on these devices for connectivity.

LONGLEASH's modus operandi involves exploiting known vulnerabilities in unpatched firmware, allowing attackers to take control of the router and use it as a proxy to redirect malicious traffic. This enables them to hide their real origin, carry out attacks on other targets, or covertly extract data. For businesses, this type of incident underscores the urgency of having a proactive cybersecurity strategy that includes not only constant firmware updates but also network monitoring and the implementation of early detection solutions.

In an environment where cybercriminals exploit any loophole, companies must go beyond basic measures. The adoption of custom applications and custom software allows for designing systems tailored to each organization's specific security needs, integrating advanced defense mechanisms. Additionally, the use of artificial intelligence and AI for businesses can automate the detection of anomalous patterns in network traffic, identifying suspicious activities like those generated by LONGLEASH. AI agents can act in real-time to isolate compromised devices, minimizing impact.

At the same time, cloud infrastructure plays a fundamental role. Organizations migrating their operations to cloud environments must ensure their providers offer robust security controls. AWS and Azure cloud services provide native tools for access management, encryption, and continuous monitoring, but require expert configuration. Q2BSTUDIO, as a software development and technology company, offers support in implementing these solutions, as well as integrating business intelligence services like Power BI to visualize security metrics and make informed decisions. The combination of a technical approach with a strategic vision allows companies not only to react to threats like UAT-7810 but also to anticipate them.

The evolution of malware like LONGLEASH demonstrates that traditional perimeter security is no longer sufficient. A defense-in-depth model is needed, ranging from designing custom applications with built-in security principles to staff training and periodic penetration testing. In this context, having a technology partner that understands both advanced threats and the operational needs of the business becomes a differentiating factor. Cooperation between cybersecurity experts, software developers, and data analysts is key to building a resilient digital environment against the most sophisticated attacks.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.