APT / THREAT GROUP
DOGLEASH
2
aliases
Last seen:Jul 15, 2026
Intelligence Profile
According to Cisco Talos, DOGLEASH is a C-based passive backdoor for Linux networking devices that binds and listens on a hardcoded port, decodes incoming TCP data with a hardcoded password, spawns threads to run actions such as executing shell commands, reading and renaming files, reporting OS information, and executing code in memory.
Threat Analysis
DOGLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
Intelligence Reports Mentioning DOGLEASH
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
SecurityWeek· Jul 8, 2026
External References
Quick Facts
TypeAPT / Threat Group
Aliases2
Also Known As
DOGLEASHelf.dogleash
External Intelligence
Malpedia: elf.dogleashResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.