APT / THREAT GROUP

LONGLEASH

2
aliases
Last seen:Jul 15, 2026

Intelligence Profile

According to Cisco Talos, LONGLEASH is a new version of the previously disclosed SHORTLEASH backdoor, built from the same C++ codebase and compiled for Linux on MIPS using the Boost.Asio asynchronous networking library along with open-source components for protobuf processing and TLS, and it offers extensive proxying and tunneling capabilities such as reverse shells, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxies, SMTP, packet redirection, and the ability to act as an intermediate command and control server while self-removing if tampering is detected.

Threat Analysis

LONGLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning LONGLEASH

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

elf.longleashLONGLEASH

External Intelligence

Malpedia: elf.longleash

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.