Chinese Hacking Group Adds Three New Backdoors to Its Router Attack Kit
The group behind a long-running campaign targeting small office routers has quietly expanded its toolbox, giving it more ways to hide inside a victim's network.

Key points
- Cisco has linked the LapDogs campaign, a long-running series of attacks on small office and home office routers, to a China-linked hacking group.
- Three new backdoors have been added to the group's toolkit: LongLeash, DogLeash, and JarLeash.
- Small office and home office routers are the primary targets, meaning the risk extends to small businesses and remote workers, not just large corporations.
- No public CVE, meaning no official flaw identifier, has been attached to this disclosure at time of writing.
A China-linked hacking group has added three new backdoors to the tools it uses to break into small office and home office routers. A backdoor is a hidden program secretly installed on a device that lets the attacker return at will, without a password.
Cisco, whose researchers track this activity, says the group is the same one behind a campaign it calls LapDogs. That campaign has focused on routers of the kind you'd find in a dentist's waiting room, a small accountancy firm, or a spare bedroom home office. We first reported on the LapDogs campaign on 8 July 2026 in our story on UAT-7810 hijacking unpatched Ruckus and ASUS routers.
The three new programs are LongLeash, DogLeash and JarLeash. Each is a different flavour of backdoor, likely written to work on different devices or to survive removal of the others. Attackers deploy multiple tools precisely so that cleaning one off a device doesn't cut their access entirely.
Why should a small business owner care?
Because a compromised router can let attackers watch all traffic flowing through it, redirect users to fake websites, or tunnel deeper into connected machines. The user at a desk inside that office would see nothing unusual.
Smaller organisations also become stepping stones. Attackers use them to reach the larger companies or government supply chains those small firms connect to.
SecurityWeek first reported on the expanded toolkit.
Should you act now?
If you run a small business or work from home, the immediate step is straightforward: check whether your router's manufacturer has issued a firmware update, which is a software patch that fixes known weaknesses, and install it. Most routers allow automatic updates in their settings menu. Enable that option if yours does.
Change the router's default administrator password if you haven't already. Default passwords are publicly known and are among the first things attackers try.
For organisations with IT teams, Cisco's disclosure is a prompt to audit which routers sit at network edges, confirm they're running current firmware, and check whether unexpected outbound connections appear in traffic logs.



