APT / THREAT GROUP
LONGLEASH
2
aliases
Last seen:Jul 15, 2026
Intelligence Profile
According to Cisco Talos, LONGLEASH is a new version of the previously disclosed SHORTLEASH backdoor, built from the same C++ codebase and compiled for Linux on MIPS using the Boost.Asio asynchronous networking library along with open-source components for protobuf processing and TLS, and it offers extensive proxying and tunneling capabilities such as reverse shells, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxies, SMTP, packet redirection, and the ability to act as an intermediate command and control server while self-removing if tampering is detected.
Threat Analysis
LONGLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
Intelligence Reports Mentioning LONGLEASH
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
SecurityWeek· Jul 8, 2026
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
The Hacker News· Jul 8, 2026
Chinese hackers develop LONGLEASH malware to expand ORB network
BleepingComputer· Jul 7, 2026
External References
Quick Facts
TypeAPT / Threat Group
Aliases2
Also Known As
elf.longleashLONGLEASH
External Intelligence
Malpedia: elf.longleashResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.