Actor Profile

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure. The actor demonstrates strategic interest in establishing persistent command and control infrastructure through the compromise of edge network devices, particularly targeting vulnerable and unpatched networking equipment. Their operations reflect a focus on building resilient C2 infrastructure by leveraging compromised routers and networking devices as operational relays, enabling obfuscation of their true origin and facilitating downstream operations.

TTPs (Tactics, Techniques, Procedures)

UAT-7810 employs LONGLEASH malware to compromise internet-facing networking devices, with a particular focus on exploiting unpatched Ruckus routers. The actor's TTPs center on initial access through exploitation of known vulnerabilities in network infrastructure devices (T1190 - Exploit Public-Facing Application). Once compromised, these devices are incorporated into an Operational Relay Box network, serving as proxy infrastructure for command and control operations (T1090 - Proxy). The targeting of edge devices provides the actor with persistent access (T1542.005 - Pre-OS Boot: TFTP Boot) and enables them to blend malicious traffic with legitimate network activity, complicating detection and attribution efforts.

Targets & Patterns

UAT-7810 targets organizations within the networking and infrastructure sectors, with specific focus on internet-facing networking devices such as routers. The actor demonstrates particular interest in Ruckus wireless networking equipment that remains unpatched and vulnerable to exploitation. This targeting pattern suggests the actor prioritizes devices that: (1) sit at network perimeters with direct internet exposure, (2) process high volumes of legitimate traffic that can mask malicious activity, (3) often lack robust security monitoring and logging capabilities, and (4) provide strategic value as relay points for subsequent operations. The focus on infrastructure devices rather than endpoint systems indicates the actor's operational priority is establishing covert C2 infrastructure rather than immediate data theft or espionage.

Historical Context

The campaign represents an evolution in UAT-7810's operational methodology, specifically their ongoing effort to expand and maintain their Operational Relay Box (ORB) network. ORB networks have been increasingly observed as a preferred infrastructure model for sophisticated threat actors seeking to obfuscate their operations through layers of compromised intermediary devices. This activity aligns with broader trends of Chinese-linked threat actors targeting network infrastructure devices for strategic positioning and long-term access. The development of LONGLEASH as a purpose-built tool for this infrastructure expansion indicates sustained investment in this operational capability.

Defensive Recommendations

  • Implement aggressive patch management for all internet-facing networking devices, prioritizing Ruckus routers and similar edge infrastructure with known vulnerabilities (T1190 mitigation)
  • Deploy network segmentation to isolate management interfaces of networking devices from direct internet exposure and restrict administrative access to trusted IP ranges only
  • Enable and centralize logging for all networking device authentication attempts, configuration changes, and firmware updates; monitor for anomalous administrative activity
  • Conduct regular firmware integrity checks on edge networking devices to detect unauthorized modifications or implant installation (T1542.005 detection)
  • Monitor for unusual outbound connections from networking infrastructure devices, particularly connections to unexpected geographic regions or known malicious infrastructure, as indicators of proxy/relay activity (T1090 detection)

---

# Geopolitical Context

Geopolitical Context

The targeting of internet-facing networking devices by UAT-7810 is consistent with a broader pattern of activity attributed to China-nexus threat actors seeking to establish persistent, distributed command-and-control infrastructure. Operational Relay Box (ORB) networks—composed of compromised edge devices such as routers and IoT equipment—enable threat actors to obfuscate malicious traffic, complicate attribution, and maintain resilient access to target environments. The focus on unpatched Ruckus routers underscores ongoing exploitation of known vulnerabilities in enterprise and small-office networking equipment, which often lack timely patch management. This activity aligns with strategic objectives to pre-position capabilities within critical infrastructure for potential espionage, disruption, or influence operations.

State Actor Alignment

UAT-7810 is assessed to be linked to China-based cyber operations, though specific state sponsorship or institutional affiliation has not been publicly confirmed. The development and deployment of specialized malware such as LONGLEASH to expand ORB networks is consistent with tradecraft observed among Chinese advanced persistent threat (APT) groups. Such infrastructure is frequently leveraged to support intelligence collection, supply chain compromise, and pre-positioning for potential future operations. The activity does not appear to be subject to current Western sanctions regimes, though it may inform future policy discussions on critical infrastructure protection and supply chain security.

Business Impacty pro region

The compromise of networking infrastructure has global implications, as ORB networks can be leveraged to target entities across multiple regions. In Europe, the targeting of edge devices poses risks to enterprise networks, telecommunications providers, and critical infrastructure operators that rely on vulnerable or inadequately secured networking equipment. The activity may also affect transatlantic cybersecurity cooperation, particularly as NATO allies and EU member states prioritize supply chain resilience and the security of 5G and edge computing environments. In the Indo-Pacific, the campaign may support broader strategic objectives related to regional influence and intelligence collection. Organizations worldwide that deploy Ruckus or similar networking devices should prioritize patch management and network segmentation to mitigate exposure.

Forecast

If UAT-7810 continues to expand its ORB network using LONGLEASH and similar tools, it is likely that additional vulnerable networking devices—particularly those from vendors with known unpatched vulnerabilities—will be targeted in the coming months. Defenders should anticipate further exploitation of edge infrastructure, with potential pivots to adjacent enterprise environments. If public attribution or technical disclosures prompt defensive countermeasures, the actor may shift to alternative device families or update malware capabilities to evade detection. Increased collaboration among vendors, CERTs, and intelligence-sharing communities will be critical to disrupting this infrastructure and reducing the operational lifespan of compromised devices.