A newly unearthed espionage campaign reveals Chinese-linked threat actors have stealthily infiltrated more than 1,000 networking devices since at least September 2023.

Dubbed LapDogs by SecurityScorecard, the campaign saw threat actors use an operational relay box (ORB) network to access compromised devices in critical infrastructure across the US and Southeast Asia.

The prolonged campaign hit IT and networking solution companies in Japan, as well as ISPs across the US and Southeast Asia, including Taiwan and South Korea.

The threat actors specifically targeted Linux and Microsoft Windows-based systems as well as IP cameras, smart IoT devices, and virtual servers, with the vast majority of infected devices being Linux-based Soho routers.

More than half of the compromised nodes (55 percent) were Ruckus Wireless access points, while more than 100 Buffalo AirStation routers, mostly deployed in Tokyo, were also infected.

In some cases, the infected devices were not just proxy nodes, but served as entry points into internal enterprise networks – what SecurityScorecard labeled as “hybrid victims.”

The attackers deployed a custom backdoor malware named ShortLeash, which created a foothold on compromised devices, enabling the hackers to infiltrate more covertly. In a more brazen move, they spoofed LAPD metadata in TLS certificates to further obfuscate their actions.

SecurityScorecard researchers described the campaign as “a vast, prolonged intrusion operation with clear intent and planning, emphasizing the need for vigilance in securing embedded devices.”

The actors gradually built up their campaign, targeting specific regions using an infrastructure tool that’s quickly becoming a weapon of choice for nation-state threat actors.

Unlike botnets, which are typically noisy and used for DDoS attacks, ORB networks allow hackers to proxy their activities through hijacked but otherwise functioning devices. In the case of LapDogs, the devices continued to work as usual, which made detection and attribution that little bit harder.

Certificate issuance analysis revealed tightly timed batches, often targeting specific countries or cities, further supporting SecurityScorecard’s findings of deliberate, goal-driven expansion rather than automated, opportunistic infection.

The unearthing of Mandarin in developer notes in the startup script and the regions where the victims were located helped the SecurityScorecard team to assess that the attackers were a China-based group.

“The focus on Southeast Asian countries and the United States is circumstantial yet noteworthy evidence as well, given the heightened focus of China-Nexus APTs on these regions,” the cybersecurity firm’s report into the campaign reads.

The newly unearthed LapDogs campaign comes amid increasing attacks from Chinese-linked threat actors and just under a year after the Salt Typhoon cyberattacks, in what was described as the "worst telecom hack” in US history.

SecurityScorecard noted that LapDogs shared similarities with another China-linked ORB operation dubbed PolarEdge. Unearthed back in February, that campaign comprised more than 2,000 infected devices around the world and has been active for a similar length of time as LapDogs. The campaigns differ in tooling, persistence mechanisms, and certificate strategy, however.

Earlier this year, Juniper Networks released an update to fight off a custom backdoor installed into its Junos OS routers by a China-linked espionage group.