Article analysis

THThe Hacker News
2w ago
TechCybersecurityTechnical Analysis

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.

Confidence0%
Tilt0%

Skim this article about "China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware": 3 key takeaways and more.

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

skim AI Analysis | The Hacker News

The Hacker News on China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware: skim's analysis surfaces 3 key takeaways. Chinese threat actor UAT-7810 is expanding its ORB network using new malware like LONGLEASH. Read the takeaways in seconds, then decide whether the full article is worth your time.

Category: Tech. News article analyzed by skim.

Summary

Chinese threat actor UAT-7810 is expanding its ORB network using new malware like LONGLEASH. They exploit vulnerabilities in networking devices, developing custom tools such as DOGLEASH and LEASHTEST. This activity aims to establish infrastructure for secondary threat actors.

Key Takeaways

  1. A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices.
  2. UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.
  3. The latest findings indicate that UAT-7810 has continued to develop their custom malware dubbed ShortLeash with a newer version that's codenamed LONGLEASH.

Statement Breakdown

  • Claimed Facts: 70% of statements the article presents as facts
  • Opinions: 20% of statements classified as editorial or subjective
  • Claims: 10% of statements surfaced for additional reader evaluation

Credibility & Bias Reasoning

Credibility assessment: The article presents detailed technical findings from a reputable cybersecurity firm, Cisco Talos. It cites specific malware names, vulnerabilities, and threat actor designations. While the subject matter is technical, the reporting is direct and informative.

Bias assessment: Technical Reporting. The article focuses on technical details of cyber threats and actor activities. It avoids emotional language or political framing, presenting information factually from a cybersecurity research perspective.

Note: This article provides a technical analysis of cyber threats. Readers should consult cybersecurity experts for in-depth interpretation and mitigation strategies.

Credibility flag: Technical Analysis

Claimed Facts (8)

  • This is a direct statement of fact about the threat actor's activities.
  • This statement identifies the actor and the network they manage, presented as factual information.
  • This provides a specific example of another actor using the infrastructure, presented as a factual link.
  • This states the development of new malware versions as a factual observation.
  • This describes a specific tool and its function as a claimed fact.
  • This describes another tool and its purpose as a claimed fact.
  • This lists specific vulnerabilities exploited, presented as factual information.
  • This details specific router models and vulnerabilities exploited, presented as factual observation.

Opinions (2)

  • The phrase 'most likely tasked with' indicates an interpretation or assessment by the researchers, not a definitively proven fact.
  • The statement 'may not be completely confident' is an interpretation of the actor's intentions and confidence level.

Claims (1)

  • While presented as a fact, the existence and deployment of 'JARLEASH' is attributed to the researchers' tracking and observation, and without further independent verification, it falls into a category of claims that require a degree of trust in the source's reporting.

Key Sources

  • The Hacker News — Cybersecurity News Outlet
  • Cisco Talos — Cybersecurity Research Group
  • Ravie Lakshmanan — Author
  • Jungsoo An — Researcher, Cisco Talos
  • Asheer Malhotra — Researcher, Cisco Talos
  • Vanja Svajcer — Researcher, Cisco Talos
  • Brandon White — Researcher, Cisco Talos

This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.

skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 8th July 2026.