What happened
Cisco Talos researchers have detailed a Chinese advanced persistent threat group, UAT-7810, that is actively developing a custom malware strain called LONGLEASH to compromise internet-exposed networking devices and fold them into a growing Operational Relay Box network known as LapDogs, which surfaced publicly in June 2025. Separately, the FBI coordinated with private-sector partners to seize hundreds of domains tied to NetNut, a residential proxy platform operated by Nasdaq-listed Israeli firm Alarum Technologies. The law enforcement action followed reporting by Krebs on Security linking NetNut to the Popa botnet, a network of compromised devices used to route malicious traffic anonymously.
Why it matters for your business
Both incidents highlight the same underlying threat vector: attackers and criminal operators are turning ordinary routers, modems, and edge devices into covert relay nodes, making malicious traffic appear to originate from legitimate residential or corporate IP addresses. For organizations, this means perimeter defenses that rely on IP reputation or geolocation blocking are increasingly unreliable. Security teams should audit all internet-facing network hardware for unauthorized firmware changes or unusual outbound connections, prioritize patching edge devices, and consider network detection and response tools capable of flagging anomalous relay behavior regardless of source IP. Businesses using third-party proxy services for ad verification, market research, or data collection should also vet those vendors carefully given the enforcement action against a publicly traded provider.
What to watch next
Alarum Technologies faces potential regulatory and shareholder scrutiny following the FBI seizure, and further legal proceedings could reveal how broadly NetNut's infrastructure was exploited. On the threat-actor side, UAT-7810's continued refinement of LONGLEASH suggests the LapDogs ORB network is still in active expansion, and additional Cisco Talos disclosures or government advisories are likely as the investigation matures. Organizations operating in sectors historically targeted by Chinese APTs — telecommunications, defense supply chains, and critical infrastructure — should treat this as an active threat requiring immediate review of their edge device inventory.
