LONGLEASH: The new hack expanding China's espionage network
The UAT-7810 group is using the LONGLEASH malware to compromise Ruckus routers and strengthen its global network of attack nodes.

The evolution of digital espionage: The LONGLEASH malware
The international cybersecurity landscape is facing a new threat. Recent investigations have identified a China-linked threat actor group, tracked as UAT-7810, which has developed a sophisticated piece of malware dubbed LONGLEASH. This malicious software has a clear goal: to expand the operational capacity of its Operational Relay Box (ORB) network.
The modus operandi: Exploiting outdated devices
The group's strategy focuses on exploiting internet-connected network devices. In particular, the attackers have targeted Ruckus routers, taking advantage of any vulnerability that has not been addressed with security patches. By compromising this equipment, the attackers not only gain access to the local network but also turn these devices into nodes for their command-and-control infrastructure.
"Using edge devices as relays allows attackers to hide their actual origin, significantly complicating forensic tracking by cybersecurity agencies," experts in the field point out.
A latent risk to critical infrastructure
This type of attack serves as a reminder that the security of a network depends on its weakest link. As seen in the case of Hack against universities: The vulnerability that exposes sensitive emails, network devices are often the most overlooked in maintenance plans. Unlike a ransomware attack, where the objective is immediate financial extortion, UAT-7810's ORB network seeks persistence and stealth for long-term espionage activities.
How to protect yourself against these threats
To mitigate the risk of being used as a node in a malicious network, it is imperative to follow these recommendations:
- Constant updating: Apply security patches immediately as soon as the manufacturer releases them.
- Network segmentation: Isolate critical infrastructure devices from end-user networks.
- Traffic monitoring: Implement intrusion detection systems that identify anomalous communication patterns to external servers.
In conclusion, the development of LONGLEASH underscores the professionalization of cyber-espionage groups. Security is not a static state, but a continuous process of vigilance and updating in a digital environment where any unprotected device is an open door for malicious actors.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...