UAT-7810 builds covert proxy networks from hijacked routers

Cisco Talos has reported on the ongoing activity of UAT-7810, a China-linked group specialising in building hidden proxy networks. The infrastructure, known as LapDogs, routes traffic through compromised devices to mask the footprints of threat actors striking high-value targets. The group expands the network by breaking into unpatched consumer and enterprise hardware, recently targeting Ruckus and ASUS routers. To maintain control and stay undetected it has rolled out a revamped toolkit featuring the LONGLEASH and DOGLEASH implants. By leasing this resilient infrastructure to secondary threat groups, UAT-7810 acts as an enabler for covert operations.

What this means for your organisation

Here your organisation is not the target but the waypoint. A hijacked router on your premises is used to attack someone else, and the traffic traces back to your IP address. That carries reputational and potentially legal consequences, on top of someone holding a lasting foothold in your network equipment. Devices at home offices and smaller sites are particularly exposed, because they rarely appear in any inventory.

Berigo recommends

  • Build an inventory of every router and network device the organisation owns or is responsible for, including small sites and home offices.
  • Update firmware on Ruckus and ASUS equipment, and replace devices no longer receiving security updates.
  • Disable internet-facing remote administration on all network equipment.
  • Monitor outbound traffic from network equipment, not only from clients and servers.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch