← All news

vulnerability

China-Linked Crew Turns Unpatched Ruckus Routers Into Relay Net

2026-07-08

A Chinese threat group tracked by Cisco Talos as UAT-7810 has been quietly building what researchers call an Operational Relay Box network. In plainer terms, a mesh of hijacked routers used to bounce attack traffic around so that by the time it reaches a target, it looks like it's coming from an ordinary device somewhere unremarkable, not from a state-aligned operator.

The appeal is deniability. If traffic arrives at a government network from a small business router in another region, the fingerprints are muddled. Attribution slows down. Defenders chase ghosts.

Old holes, new problem

The way in is thoroughly unglamorous. UAT-7810 is relying on known, unpatched vulnerabilities in internet-facing Ruckus gear, specifically CVE-2020-22653, CVE-2020-22658 and CVE-2023-25717, along with CVE-2025-2492 in ASUS AiCloud routers. Nothing exotic. Nothing that required a zero-day. Just devices that never got the updates their vendors shipped, sitting on the public internet, waiting to belong to someone else.

This is the part that tends to get glossed over in the excitement about advanced threat actors. A significant chunk of state-linked activity runs on infrastructure that any competent junior admin could have patched a year ago.

A grown-up toolkit

Talos also documented a fresh set of custom tools. The headline addition is LONGLEASH, a beefier successor to the group's earlier SHORTLEASH backdoor. Alongside it:

  • DOGLEASH, a lightweight Linux backdoor pushed onto compromised hosts through a web shell. It listens on a TCP port and takes commands after a hardcoded password check.
  • JARLEASH, a Java-based admin utility with FTP, SFTP and Netcat server functionality baked in.
  • LEASHTEST, a diagnostic used to check whether a given MIPS-based IoT device can actually run the group's malware without falling over.

That last one is telling. When you're building something at the scale of a global relay network, you need to know in advance which cheap plastic router is going to cooperate and which will crash the moment you touch it.

Shared infrastructure, wider blast radius

Talos reports that the relay network isn't exclusive to UAT-7810. It's being shared with other China-aligned groups, including UAT-5918. So a single compromised router in a branch office isn't just fuelling one campaign, it may be quietly relaying operations for several teams at once.

The bit that should bother you

Most of the devices making up this network are not in datacentres. They're in small offices, retail sites, home offices and branch locations. They sit well outside the visibility of any SOC. They rarely get patched. They rarely appear on an asset inventory. Nobody logs into them from one quarter to the next.

Once one gets enrolled into an ORB network, the owner has almost no chance of noticing. The router still works. The internet still works. It's just also quietly forwarding someone else's traffic to a target on the other side of the world.

The obvious question for any organisation with distributed sites is a boring one: do you actually know what's sitting at the edge of every branch office, and when it was last updated? For a lot of businesses, the honest answer is not really.

China-Linked Crew Turns Unpatched Ruckus Routers Into Relay Net | RiskSense