A sophisticated cyber‑espionage campaign has compromised over 1,000 small‑office/home‑office (SOHO) devices globally, primarily targeting China‑connected infrastructure. The network, dubbed Operational Relay Box (ORB) and internally codenamed LapDogs by SecurityScorecard’s STRIKE team, is thought to be tied to a China-linked hacking group.

Wide Geographic Reach and Diverse Targets
SecurityScorecard reports that LapDogs features a high concentration of hacked devices across the U.S. and Southeast Asia , with additional victims identified in Japan, South Korea, Hong Kong, and Taiwan. Affected entities span various sectors including IT, networking, real estate, and media. Among the exploited hardware and services are products from Ruckus Wireless, ASUS, Buffalo, Cisco-Linksys, Cross DVR, D-Link, Microsoft, Panasonic, and Synology.

ShortLeash Backdoor: Custom and Covert
Central to LapDogs is a bespoke backdoor known as ShortLeash. Upon infection, the malware deploys a bogus Nginx web server and self-signed TLS certificate bearing the issuer name “LAPD”—an intentional mimicry of the Los Angeles Police Department, lending the campaign its alias.

ShortLeash primarily targets Linux-based SOHO devices, though evidence suggests Windows variants exist. The malware integrates into the system via a shell script, exploiting older but still vulnerable N-day flaws such as CVE-2015-1548 and CVE-2017-17663.

Timeline and Infection Patterns
SecurityScorecard identified the earliest LapDogs activity on September 6, 2023, in Taiwan, with the second wave emerging on January 19, 2024. Campaigns typically infect batches of up to 60 devices, with at least 162 distinct intrusion clusters recorded to date. Analysts believe this staggered approach helps maintain stealth and operational flexibility.

Comparison With PolarEdge but Distinct Methods
LapDogs shows parallels with another ORB network known as PolarEdge, disclosed by Sekoia earlier in February 2025. Both networks exploit router and IoT device vulnerabilities to construct sprawling infrastructure. However, STRIKE emphasizes that LapDogs is a separate entity, notable for differences in infection strategies, persistence mechanisms, and its inclusion of virtual private servers (VPS) and Windows systems.

While PolarEdge installs web shells by overwriting CGI scripts, ShortLeash embeds itself as a systemd .service file, ensuring root-level persistence after reboots.

Link to Known Chinese Threat Actors
There’s medium confidence attribution tying the UAT‑5918 group—a known China-linked actor—to use of LapDogs in operations against Taiwan. It remains unclear if UAT‑5918 is the original creator or simply a client of the infrastructure.

Security researchers warn that ORB architectures are increasingly favored by Chinese nation-state actors. Google, Mandiant, Sygnia, and SentinelOne have individually documented similar networks, noting they’re employed throughout all phases of intrusion—from reconnaissance, anonymized browsing, netflow collection, scanning, staging, command and control (C2), to staged data exfiltration.

As SecurityScorecard analysts explain, “While both ORBs and botnets commonly consist of a large set of compromised legiti­mate internet‑facing devices or virtual services, ORB networks are more like Swiss Army knives… relaying exfiltrated data up the stream”.


Why LapDogs Matters: What Organizations Should Know

  1. Persistent, multi‑layered access
    ShortLeash’s integration as a root‑level service ensures longevity within infected systems, allowing adversaries to maintain control long after initial exploitation.
  2. Broad, unspecific targeting
    The campaign’s low‑volume, batch‑based infections across diverse sectors and regions indicate intent for long‑term infrastructure, not quick data grabs.
  3. Weaponization of dated vulnerabilities
    Despite the age of exploited flaws, their continued presence on internet‑facing devices underscores persistent patch management gaps.
  4. Global interdependence
    Cross‑regional nature of attacks—spanning Asia to North America—showcases the interconnected risk landscape and the need for unified defense strategies.

Defensive Strategies for Organizations and ISPs

  • Audit exposed devices: Scan for N-day vulnerabilities (including CVE-2015‑1548, CVE-2017‑17663) in SOHO and mid-tier network hardware.
  • Harden configurations: Employ strong firmware management, disable unused services, isolate IoT appliances from core networks.
  • Monitor for anomalies: Watch for unauthorized Nginx instances, unusual TLS certificates (look for “LAPD” issuer), and unfamiliar .service files.
  • Pursue threat intelligence collaboration: Share findings and IOCs with platforms like Mandiant, Sekoia, and SecurityScorecard.

Bottom Line
LapDogs exemplifies how threat actors are evolving beyond simple botnets, leveraging legitimate hardware to build stealthy, resilient cyber-espionage infrastructures. With an estimated 1,000+ infected devices and counting, proactive measures and advanced threat detection are essential to contain these ORB-based threats.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *