Back to Intel

Intel Node

UAT-7810 continues building ORB networks using new malware

mediumapt2026-07-07T10:00:05+00:00source excerpt
aptmalwarevulnerabilitycveexploitationlinux

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.

Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025. UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets.

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware, dubbed “SHORTLEASH,” with a newer version already being developed and hosted on attacker-controlled infrastructure.

Read Original Source