
UAT-7810 LONGLEASH ORB Network Expansion Campaign
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Detection Strategy Name | ID | Analytic ID | Analytic Description |
|---|---|---|---|
DET0080 | AN0225 | Monitor internet-facing routers for anomalous outbound connections, unauthorized binary/firmware writes, and unexpected iptables rule changes following known Ruckus/ASUS CVE exploitation attempts. | |
DET0359 | AN1024 | Monitor NetFlow and full packet capture for encrypted traffic between routers on non-standard ports (99, 2222, 8088) and for reuse of the self-signed TLS certificate fingerprint associated with LONGLEASH infrastructure. | |
DET0227 | AN0634 | Identify devices listening on ports 99, 2222, or 8088 with self-signed TLS certificates bearing the generic subject_dn "CN=exploit", indicative of DOGLEASH or JARLEASH deployment. |