#ShortLeash
LAPDogs ARE on the short leash, of capital!
June 24, 2025 at 4:27 PM
Waiting for politicians to convince us we should have a FOUR year parliamentary term instead of just THREE.

National never campaigned on slashing funding for our hospitals!!

#WhenHellFreezesOver

#ShortLeash

#NationalNotFitToGovern
April 26, 2024 at 4:05 AM
🚨 China-linked #LapDogs campaign has been active since 2023, dropping the #ShortLeash backdoor and using hacked routers to hide espionage and data theft.

Read: hackread.com/china-lapdog...

#CyberSecurity #China #CyberAttack #IoT #CyberEspionage
China-linked LapDogs Campaign Drops ShortLeash Backdoor with Fake Certs
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
June 23, 2025 at 9:35 PM
THIS IS WHY I WILL NOT SUPPORT A FOUR YEAR PARLIAMENTARY TERM.

Unless politicians grow up, #ShortLeash
New: Prime Minister Christopher Luxon says threats by ministers Shane Jones and David Seymour to reform or close down the Waitangi Tribunal were "ill-considered", as legal experts say they may have breached the Cabinet Manual.
newsroom.co.nz/2024/04/19/m...
Ministers accused of Cabinet Manual breach with threats to Waitangi Tribunal
Shane Jones said he was looking forward to reforming the tribunal while David Seymour suggested it could be shut down.
newsroom.co.nz
April 19, 2024 at 2:39 AM
ANYWAY the stuff got delivered two days ago, the replacement ears, a shortleash and a belt mounted leash holder attachment, very happy, the shortleash feels great to tug on and the ears are bright with a white edge which matches my hoods colours, time to attach the ears and put this all behind me…
July 31, 2025 at 12:53 PM
3 batters only, John Schneider! If the reliever isn't getting outs, pull him!
#bluejays #shortleash
a man in a suit is holding his finger to his nose .
ALT: a man in a suit is holding his finger to his nose .
media.tenor.com
October 16, 2025 at 2:22 AM
SecurityScorecard has discovered a new botnet used by Chinese hackers to hide their attacks.

Named LapDogs, the botnet runs on top of a custom backdoor named ShortLeash.

The botnet has infected more than 1,000 devices, with most being SOHO routers.

securityscorecard.com/blog/unmaski...
Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign
SecurityScorecard’s STRIKE team uncovered a new China-Nexus ORB Network targeting the United States and Southeast Asia. Read the report to gain an in-depth look at the LapDogs ORB network, its custom ...
securityscorecard.com
June 24, 2025 at 12:42 PM
May 1, 2024 at 1:18 PM
“Once installed, it sets up a fake Nginx web server and generates a self-signed TLS certificate spoofing the LAPD. That certificate became a key fingerprint and helped researchers trace over 1,000 infected nodes worldwide.”
www.helpnetsecurity.com/2025/06/23/l...
Stealthy backdoor found hiding in SOHO devices running Linux - Help Net Security
LapDogs uses the ShortLeash backdoor to quietly compromise Linux-based SOHO devices, forming a stealthy ORB network for targeted operations.
www.helpnetsecurity.com
June 24, 2025 at 12:17 PM
Chinese hackers tracked as UAT-7810 are expanding an ORB network by compromising exposed routers, especially unpatched Ruckus devices, and deploying new tools like LONGLEASH and DOGLEASH to proxy traffic through regional systems. #China #Ruckus
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as UAT-7810 are expanding their Operational Relay Box infrastructure by compromising internet-facing routers, especially unpatched Ruckus devices, to proxy traffic through legitimate-looking regional systems. Cisco Talos found new tools in the campaign, including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, alongside exploitation of multiple router vulnerabilities. #UAT-7810 #LONGLEASH #SHORTLEASH #DOGLEASH #JARLEASH #LEASHTEST #Ruckus #ASUSAiCloud #UAT-5918
www.hendryadrian.com
July 7, 2026 at 8:00 PM
Cisco Talos is monitoring UAT-7810, an APT actor developing the LapDogs ORB network. New malware includes "LONGLEASH," an enhanced version of "SHORTLEASH," and two additional backdoors: "DOGLEASH" (C-based) and "JARLEASH" (JAVA-based).
UAT-7810 continues building ORB networks using new malware
blog.talosintelligence.com
July 8, 2026 at 2:39 PM
中国関連APT、新たなマルウェア使いORBネットワークを引き続き拡大 | Codebook

... マルウェア「SHORTLEASH」の開発を続けていることを示している。同調査チームはSHORTLEASHの最新版マルウェアを「LONGLEASH」と名付け、加えてUAT-7810の ...
codebook.machinarecord.com/threatreport...
中国関連APT、新たなマルウェア使いORBネットワークを引き続き拡大 | Codebook|Security News
中国関連のAPT脅威アクターとみられる「UAT-7810」は、Ruckusルーターなどのネットワーキング端末を侵害してOperational Relay Box(ORB)ネットワークを拡大させるため、自身のマルウェアを積極的に進化させているという。Cisco Talosが報告した。
codebook.machinarecord.com
July 8, 2026 at 12:53 PM
LONGLEASHマルウェアがリバースシェル、プロキシ、中継C2機能を追加

UAT-7810という攻撃者が維持するマルウェアに重大なアップグレードが確認されました。以前報告されたSHORTLEASHインプラントの後継となるLONGLEASHは、リバースシェル、複数プロトコルに対応したプロキシ機能、そして中継的なコマンド&コントロール(C2)転送機能を備えています。 LONGLEASHはSHO...
LONGLEASHマルウェアがリバースシェル、プロキシ、中継C2機能を追加
UAT-7810という攻撃者が維持するマルウェアに重大なアップグレードが確認されました。以前報告されたSHORTLEASHインプラントの後継となるLONGLEASHは、リバースシェル、複数プロトコルに対応したプロキシ機能、そして中継的なコマンド&コントロール(C2)転送機能を備えています。 LONGLEASHはSHO
blackhatnews.tokyo
July 8, 2026 at 5:52 AM
Notícia da SecurityWeek

"Chinese APT Hacking Routers to Build Espionage Infrastructure" #bolhasec
Chinese APT Hacking Routers to Build Espionage Infrastructure
A Chinese APT has been infecting SOHO routers with the ShortLeash backdoor to build stealthy espionage infrastructure.
www.securityweek.com
July 22, 2025 at 3:30 PM
We immediately alerted customers and reported findings to the Department of Energy.

Full analysis with IOCs: expel.com/blog/gonzo-t...
Gonzo threat hunting: LapDogs & ShortLeash
Follow along as a senior detection & response engineer locates threat actors using SOHO devices & ORB networks, Gonzo-style.
expel.com
September 25, 2025 at 5:39 PM
So long Huddy. #WorldSeries #shortleash
November 14, 2024 at 4:05 PM
Chinesische Hacker haben über 1.000 SOHO-Geräte infiziert
Dutzende Cybercrime-Kampagnen mit Fokus auf Asien und die USA wurden als angebliche LAPD-Aktionen getarnt. FOTOGRIN – shutterstock.com Cybersecurity-Experten haben ein Netzwerk von mehr als 1.000 kompromittierten Small-Office- und Home-Office-Geräten (SOHO) entdeckt. Die Devices wurden laut den Experten dazu genutzt, eine langwierige Cyberspionage-Infrastrukturkampagne für chinesische Hacker-Gruppen zu ermöglichen. ## **ShortLeash als zentrale Schadsoftware** Das Strike-Team von SecurityScorecard entdeckte das dazugehörige Operational-Relay-Box (ORB)-Netzwerk und gab ihm den Namen LapDogs. Bei der Analyse fanden die Forschenden heraus, dass die Opfer vor allem aus den USA und Südostasien stammten. Besonders betroffen waren Japan, Südkorea, Hongkong und Taiwan. Die Malware scheint dabei vor allem bei chinesischen Hackern beliebt gewesen zu sein, wie Berichte von Check Point, Sygnia und SentinelOne zeigen. Die Schadsoftware ShortLeash steht dabei im Zentrum der LapDogs-Kampagne, wie die Experten herausfanden. Sie infiziert vor allem Linux-basierte SOHO-Geräte über bekannte Schwachstellen, sogenannte N-Day-Exploits. Dabei tarnt sie sich mit einem gefälschten Nginx-Webserver sowie einem selbstsignierten Zertifikat, welches fälschlicherweise vom Los Angeles Police Department (LAPD) stammen soll. Eine Windows-Version der Backdoor existiert ebenfalls und wird laut den Experten vermutlich über ein Shell-Skript verbreitet. ## **Kleine Chargen, viele Angriffe** Erste Aktivitäten der LapDogs-Kampagne wurden am 6. September 2023 in Taiwan entdeckt, gefolgt von einem weiteren Angriff im Januar 2024. Die Attacken erfolgten dabei offenbar in kleinen Chargen mit maximal 60 infizierten Geräten. Insgesamt identifizierten die Experten bislang 162 solcher Kampagnen. Sie entdeckten auch, dass die meisten Zertifikate innerhalb einer Gruppe im Abstand von weniger als zwei Sekunden generiert wurden. Das lässt laut SecurityScorecard darauf schließen, dass es sich um automatisierte Angriffe anstatt um manuelle Infektionen handelt. Diese ähneln dem Cluster „PolarEdge“, das ebenfalls IoT-Sicherheitslücken ausnutzt. Trotz Überschneidungen gelten LapDogs und PolarEdge aber als getrennte Gruppen, da sich ihre Infektionsmethoden und Ziele unterscheiden. Die Experten von SecurityScorecard halten fest, dass die PolarEdge-Backdoor das CGI-Skript der Geräte durch die vom Betreiber festgelegte Webshell ersetzt. ## **Chinesische Meldung bei Fehler** ShortLeash füge sich dagegen lediglich als .service-Datei in das Systemverzeichnis ein und sorge dafür, dass der Dienst nach einem Neustart mit Root-Rechten weiterlaufe. Hierfür überprüft die Malware, ob auf dem System Ubuntu oder CentOS läuft, und installiert sich dann entsprechend. Nach der Installation benennt das Skript einen Systemdienst um und ersetzt ihn, damit er verborgen und dauerhaft bleibt. Hiermit stellt der Eindringling sicher, dass er bei jedem Neustart ausgeführt wird. Wird das Betriebssystem allerdings nicht erkannt, zeigt es eine Meldung in Mandarin mit dem Text „Unbekanntes System“ an. Die Experten vermuten zudem, dass die mit China verbundene und als UAT-5918 bekannte Hackergruppe LapDogs bei mindestens einer ihrer auf Taiwan gerichteten Operationen eingesetzt hat. Es ist allerdings nicht bekannt, ob UAT-5918 hinter dem Netzwerk steckt oder nur ein Client ist. ## **Angriffe auf namhafte Hersteller aus einer Hand** Bei den aufgedeckten Angriffen konzentrierten die Kriminellen sich vor allem auf Geräte aus den Bereichen IT, Netzwerke, Immobilien und Medien. Hersteller waren unter anderem namhafte Marken wie ASUS, Cisco-Linksys, D-Link und Microsoft. Die Experten warnen allerdings auch, dass das Netzwerk stetig wächst, da die Infektion nur von der Kompatibilität mit dem Betriebssystem abhängt und nicht von der Hardware. Das mache viele SOHO-Geräte anfällig, wobei die Systeme, auf denen Dienste wie GoAhead-Webanwendungen besonders gefährdet seien.
www.csoonline.com
July 1, 2025 at 4:28 PM
China-linked LapDogs Campaign Drops ShortLeash Backdoor with Fake Certs

ShortLeash backdoor, used in the China-linked LapDogs campaign since 2023, enables stealth access, persistence, and data theft via compromised SOHO routers and fake certs.

#hackernews #news
China-linked LapDogs Campaign Drops ShortLeash Backdoor with Fake Certs
ShortLeash backdoor, used in the China-linked LapDogs campaign since 2023, enables stealth access, persistence, and data theft via compromised SOHO routers and fake certs.
hackread.com
June 24, 2025 at 10:31 PM
Feed: "Help Net Security"
By: Mirko Zorz on Monday, June 23, 2025
Stealthy backdoor found hiding in SOHO devices running Linux
LapDogs uses the ShortLeash backdoor to quietly compromise Linux-based SOHO devices, forming a stealthy ORB network for targeted operations.
www.helpnetsecurity.com
June 23, 2025 at 10:03 AM
January 24, 2026 at 9:37 PM