s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.longleash

📛 Threat Title

Malware family: LONGLEASH

Category: LONGLEASH First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.longleash`. Printable name: LONGLEASH.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:dailysecurityreview.com

    Cisco Talos disclosed UAT-7810, a China-linked APT building the LapDogs ORB relay network using LONGLEASH malware on compromised Ruckus and ASUS routers.

  • web:gbhackers.com

    A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH , a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell.

  • web:izoologic.com

    UAT-7810 expands its ORB network with LONGLEASH malware , targeting internet-facing devices to enhance stealth, persistence, and cyber espionage.

  • web:radar.offseq.com

    Detailed information about Chinese hackers develop LONGLEASH malware to expand ORB network. Get real-time updates, technical details, and mitigation strategies.

  • web:socprime.com

    Summary The China-linked APT group UAT-7810 is continuing to expand its LapDogs Operational Relay Box network with a toolkit of custom malware that includes LONGLEASH , DOGLEASH, and JARLEASH. The actor focuses on embedded devices and networking hardware to build proxy infrastructure that can later be leveraged by secondary threat actors.

  • web:www.bleepingcomputer.com

    Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily ...

  • web:www.brinztech.com

    The "Leash" Malware Suite: UAT-7810 has moved beyond its previous "ShortLeash" tool to a more modular, resilient toolkit: LONGLEASH : A sophisticated, asynchronous backdoor (based on the Boost.Asio library) that acts as the primary proxying engine. It supports multi-protocol relaying, including HTTP, DNS, SOCKS, TCP, ICMP, and UDP.

  • web:www.enigma-global.com

    Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.