A cyber espionage operation called LapDogs, reportedly linked to China-aligned threat actors, targeted devices in multiple countries including the US, Japan, South Korea, Taiwan, and Hong Kong.
The operation involved hijacking SOHO routers and IoT devices, turning them into Operational Relay Boxes (ORBs) for extended surveillance.
The hackers used a custom backdoor named ShortLeash to gain root-level access and remain undetected in compromised devices, with some devices acting as gateways to infiltrate internal networks.
SecurityScorecard highlighted LapDogs' strategic and geo-targeted approach, emphasizing the challenge in detecting the malware due to the spoofing of legitimate security certificates.