Back to all lessons
Awareness Lessons
3 months ago

China-Linked APT Targets Unpatched SOHO Routers with New Backdoor Suite

UAT-7810 is exploiting known, unpatched vulnerabilities in SOHO routers such as Ruckus devices to deploy sophisticated backdoors including LongLeash, DogLeash, and JarLeash. The root cause is a failure to apply available patches to internet-facing network appliances, leaving well-documented attack surfaces open to exploitation. SOHO routers are frequently overlooked in enterprise patch cycles despite being critical network entry points. This matters because compromised routers provide persistent, stealthy footholds that enable long-term espionage operations, often going undetected for extended periods.

Tactical Insight

Immediate actions

  • Audit all SOHO and edge routers for firmware versions and apply vendor-released security patches immediately.
  • Conduct a vulnerability scan targeting internet-facing network appliances to identify devices running outdated or end-of-life firmware.
  • Isolate any routers suspected of compromise from the broader network pending forensic investigation.

Long-term improvements

  • Establish a formal patch management policy that explicitly includes network appliances, routers, and OT/IoT devices.
  • Maintain a continuously updated asset inventory covering all network edge devices to ensure no appliance is excluded from patch cycles.
  • Implement network segmentation to ensure SOHO routers cannot directly reach sensitive internal systems or data repositories.

Detection measures

  • Deploy network traffic monitoring and anomaly detection on all edge devices to identify unusual outbound connections indicative of backdoor activity.
  • Collect and centralize syslog data from all routers and network appliances into a SIEM for correlation and alerting.
  • Subscribe to threat intelligence feeds tracking APT TTPs to receive early warning of campaigns targeting your router models.