China-Linked UAT-7810 Expands ORB Network with New LONGLEASH Malware
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025.
Why it matters
This state-sponsored activity represents a significant threat to network security and infrastructure resilience.
SOC impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Recommended actions
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Executive Summary
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025. This state-sponsored activity represents a significant threat to network security and infrastructure resilience.
SOC Impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Detection and Hunting Focus
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Why It Matters
This state-sponsored activity represents a significant threat to network security and infrastructure resilience.