China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
By breaching internet-facing networking equipment, a Chinese threat actor known as UAT-7810 is actively honing its custom malware to grow its Operational Relay Box (ORB) network.
UAT-7810 is an advanced persistent threat (APT) actor that is in charge of sustaining and spreading LapDogs, an ORB network that was initially discovered in June 2025, according to research by Cisco Talos.
According to researchers Jungsoo An, Asheer Malhotra, Vanja Svajcer, and Brandon White, UAT-7810 is most likely tasked with creating Operational Relay Box (ORB) networks that can subsequently be used by related secondary threat actors to carry out their own malicious assaults against high value targets.
UAT-5918 is one such China-nexus threat actor that has used the infrastructure in its own assaults. ...

