APT / THREAT GROUP

DOGLEASH

2
aliases
Last seen:Jul 15, 2026

Intelligence Profile

According to Cisco Talos, DOGLEASH is a C-based passive backdoor for Linux networking devices that binds and listens on a hardcoded port, decodes incoming TCP data with a hardcoded password, spawns threads to run actions such as executing shell commands, reading and renaming files, reporting OS information, and executing code in memory.

Threat Analysis

DOGLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning DOGLEASH

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

DOGLEASHelf.dogleash

External Intelligence

Malpedia: elf.dogleash

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.