Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024

June 20, 2026

Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure

June 20, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » China’s ‘LapDogs’ Network Thrives on Backdoored SOHO Devices
Uncategorized

China’s ‘LapDogs’ Network Thrives on Backdoored SOHO Devices

Staff WriterBy Staff WriterJune 24, 2025No Comments5 Mins Read7 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Researchers have discovered yet another network of operational relay boxes (ORBs) controlled by suspected Chinese nation-state actors for cyber-espionage purposes.

According to SecurityScorecard’s STRIKE research team, the ORB network, nicknamed “LapDogs,” has infected more than 1,000 nodes with a custom backdoor against “highly localized targets” in the US as well as Japan, South Korea, Hong Kong, and Taiwan. The researchers attributed the network to China-nexus actors with moderate confidence and noted similarities between LapDogs and other Chinese state-sponsored ORB networks.

ORB networks have become a hallmark of increased threat activity from the People’s Republic of China (PRC). Various cybersecurity vendors have detailed how espionage actors in recent years have built botnet-like networks, featuring routers, Internet of Things (IoT) devices and virtual private servers, not to launch direct attacks but to provide infrastructure that disguises malicious operations as legitimate traffic.

SecurityScorecard called ORB networks an emerging threat because they act as a “Swiss Army knife” that attackers can use to covertly conduct reconnaissance, vulnerability scanning, anonymized browsing, and command-and-control (C2) operations for larger attacks.

Related:DHS Warns of Rise in Cyberattacks in Light of US-Iran Conflict

“The rise of ORB Networks as a main TTP for China-nexus APTs poses a significant challenge to traditional security best-practices by eroding the importance of Indicators of Compromise (IOC) tracking, due to the sheer number of nodes and the rapid pace at which they change,” the report said.

LapDogs’ Cyberattack Bite

STRIKE researchers recently identified LapDogs, which infects Linux-based small office/home office (SOHO), but found the ORB network has been active since at least September 2023. The research team also noted that LapDogs has steadily grown in size over the past two years.

According to the report, the campaign has affected ISPs, hardware vendors, and “specific organizations” in the IT, networking, real estate, and media sectors. For example, STRIKE researchers said LapDogs compromised devices at a UK-based media company as well as a municipal services office, a real estate company, and IT and network solutions companies in Japan.

SecurityScorecard warned that infected nodes could point to serious threats to the owning organizations beyond having compromised devices used for malicious cyber activity.

“Every node in the LapDogs ORB can be used by a threat actor to further access the internal network the node is connected to, therefore each owner of a compromised device might be further victimised and should take preventative measures,” the research team said.

Related:Hackers Post Dozens of Malicious Copycat Repos to GitHub

More than half of the infected devices are Ruckus Wireless access points, while products from a number of other vendors’ were also impacted, including ASUS, Buffalo Technology, Cisco Linksys, D-Link, Microsoft, Panasonic, and Synology.

The report also highlighted that ORB networks are often used by multiple threat actors for separate campaigns. In the case of LapDogs, Security Scorecard said the network has been used at least once by a threat group tracked as UAT-5918 in cyber-espionage operations against Taiwan. However, STRIKE researchers said they could not determine whether UAT-5918 was the operator of LapDogs or just a client of the ORB network.

TLS Certificate Abuse

SecurityScorecard noted several aspects of LapDogs that distinguished it from previous ORB network activity. First, the threat actors used a custom backdoor, dubbed “ShortLeash,” to maintain persistent access on compromised devices.

Second, the ShortLeash backdoor ShortLeash generates unique, self-signed TLS certificates with spoofed metadata for each node. The metadata presents the certificates as signed by the Los Angeles Police Department (LAPD) and suggests the threat actors are attempting to masquerade infected nodes as legitimate LAPD network devices, hence SecurityScorecard’s nickname “LapDogs.”

Related:Iran-Israel War Triggers a Maelstrom in Cyberspace

It’s unclear, however, if there was any specific reason for spoofing the LAPD, according to Gilad F. Maizles, security researcher at SecurityScorecard. “It could be an inside joke by the operator, something not uncommon among Chinese APTs,” he says. “While we did observe some compromised devices in the Los Angeles area, they were neither the first nor the most prominent in the network. We also found no evidence of direct targeting or compromise of the LAPD itself.”

Self-signed certificates are often seen as security risks because they are not validated by third-party certificate authorities. Many systems and software will issue alerts or warnings for the presence of self-signed certificates in a trust chain.

However, the warnings are not always acknowledged, and the best practices around self-signed certificates are not always followed — even by the vendors themselves.

“Most of the devices we encountered (such as Ruckus Wireless devices or Buffalo Tech AirStation) have a built-in Web server that is used as a configuration interface and can be browsed externally from the internet,” Maizles says. “These Web UI servers, in most cases, were using a self-signed certificate generated by the device itself as well. Any alerts or rules that target self-signed certificates will be triggered anytime a legitimate access is attempted to the Web UI server, so rules and alerts for access to these devices are most likely ignored or white-listed with regard to self-signed certificates.”

Maizles says this is partially why ORB networks and botnets typically target SOHO devices, “as they are not only ill-managed and unpatched, but also come predesigned with lower security standards that are rarely addressed by the owners.”

SecurityScorecard released indicators of compromise for LapDogs, including network fingerprints for the spoofed TLS certificates as well as C2 domains and signatures for the ShortLeash backdoor. As with botnet defenses, organizations should ensure their connected devices are updated and remove any default credentials. Network administrators should also monitor for suspicious connections and traffic flows.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrezor Support Platform Targeted in Crypto Theft Phishing Scams
Next Article Navigating the Interplay of Generative AI and Security
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Salesforce Disables Klue App After Data Breach from Token Abuse

June 19, 2026

Stay Safe: Top Tech Tip to Avoid World Cup Ticket Scams Online

June 18, 2026

SoftBank & OpenAI Unite to Defend Japan from Cyberattacks

June 16, 2026
Leave A Reply Cancel Reply

Latest Posts

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Threat Actor Deploys Advanced EDR-Crushing Tools in Ransomware Platform

June 19, 2026

CISA Flags LiteSpeed cPanel Plugin Vulnerability Amid Active Exploitation

June 19, 2026

INC Ransomware Launches Rust-Based Attacks on Windows, Linux, and ESXi

June 19, 2026
Don't Miss

Salesforce Disables Klue App After Data Breach from Token Abuse

By Staff WriterJune 19, 2026

Quick Takeaways Salesforce disabled Klue Battlecards app integration after detecting unauthorized activity linked to a…

Stay Safe: Top Tech Tip to Avoid World Cup Ticket Scams Online

June 18, 2026

SoftBank & OpenAI Unite to Defend Japan from Cyberattacks

June 16, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes
  • Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024
  • Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure
  • Threat Actor Deploys Advanced EDR-Crushing Tools in Ransomware Platform
  • Fortinet VPN vulnerability exploited for remote access compromise
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024

June 20, 2026

Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure

June 20, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202633 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202528 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.