Chinese hackers hijack unpatched routers to build a stealth relay network
A group Cisco Talos calls UAT-7810 is breaking into Ruckus and ASUS routers to hide the tracks of other China-linked spying crews.

Key points
- Cisco Talos has linked a Chinese hacking crew it calls UAT-7810 to a growing network of hijacked routers used to hide other China-aligned spies.
- The group exploits known, unpatched flaws in Ruckus routers and ASUS AiCloud routers: CVE-2023-25717 and CVE-2025-2492 among them.
- Researchers identified four new pieces of malware tied to the campaign: LONGLEASH, DOGLEASH, JARLEASH and LEASHTEST.
- LONGLEASH is an upgraded backdoor that can proxy traffic, open reverse shells and act as a middle-man command server between infected nodes.
- The relay network also supports UAT-5918, another China-aligned group known for targeting Taiwan.
A Chinese hacking crew is quietly turning home and office routers into a private smokescreen for other state-linked spies.
Cisco Talos, the research arm of Cisco, published new findings this week on a group it tracks as UAT-7810. The crew builds what security researchers call an Operational Relay Box network, or ORB: a web of hacked internet devices the attackers bounce their traffic through, so their activity looks like it's coming from an ordinary router in someone's office rather than from China.
They didn't write clever new exploits to get there. They walked through doors that owners left unlocked.
How did the hackers get in?
They used old, publicly known flaws in internet-facing routers that had never been patched.
Talos says UAT-7810 focuses on Ruckus routers, exploiting CVE-2020-22653, CVE-2020-22658 and CVE-2023-25717. That last one lets an attacker run commands on the device without logging in. The group also targets ASUS AiCloud routers through CVE-2025-2492, a bug that allows unauthenticated access to functions that should be off-limits.
None of these are zero-days. They're what the industry calls n-days: fixes exist, but plenty of owners never install them. Our earlier story on a hidden admin backdoor in Tenda routers from 7 July 2026 showed the same pattern: known flaws sitting open long after a patch landed.
What the malware does
Once inside, the hackers drop a toolkit Talos has now mapped in detail. The campaign centres on a backdoor called LONGLEASH, an upgraded version of an older tool named SHORTLEASH, first documented by SecurityScorecard in 2025.
The new build can open a reverse shell, a hidden command line back to the attackers. It can also shuffle traffic through the infected router, operate as an SMTP mail client and server, handle TLS encryption certificates and wipe itself if it detects tampering. Most importantly for the ORB network, it acts as a middle-man command server, forwarding orders and stolen data between infected devices. One hacked router can quietly serve several spying operations at once.
Three other tools sit alongside it. DOGLEASH is a lightweight Linux backdoor deployed through web shell scripts, protected by a hardcoded password. JARLEASH is a Java-based admin panel giving attackers browser-based file management and file-transfer servers. LEASHTEST is a small utility that checks whether a target MIPS-based device, a chip family common in cheap routers and other connected gear, can actually run their malware.
Who benefits from the relay network?
Other Chinese groups. Talos says the ORB network built by UAT-7810 is used by UAT-5918, a separate China-aligned crew known for targeting organisations in Taiwan. Google's Mandiant unit documented this style of shared relay infrastructure previously, noting it makes attribution far harder because the traffic hitting a victim looks local and routine.
Should you worry about your router?
If you own a Ruckus or ASUS router at home or in a small office, check the admin page for a firmware update now and install it. Devices years past vendor support should be replaced. A router that's never been patched is exactly what these groups are hunting for, and the sophistication here is operational, not technical. The exploits are old. The owners just didn't act.
Talos has published a full list of technical indicators for defenders in its report.



