Skip to content

Malware

ShortLeash

According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network.

ShortLeash is a Windows malware family.

Background

Per STRIKE, ShortLeash is a bespoke backdoor deployed to build out an ORB network. For each node it produces a distinct self-signed TLS certificate carrying forged metadata. Examining these certificates exposed more than 1000 active nodes worldwide, and the targeting pattern points to China-Nexus APTs.


Source: Malpedia (Fraunhofer FKIE).