Hidden in the Overlay Analysis of Backdoor Leveraging Encrypted Overlay Communications for ORB
In recent years, compromised edge devices and routers have increasingly been abused by advanced persistent threat (APT) actors as Operational Relay Boxes (ORBs), providing infrastructure that conceals malicious activities and supports long-term operations. The ORB infrastructure and malware discussed in this presentation target router platforms widely deployed in regions including East Asia, making them a potentially significant threat in these areas.
This presentation covers CJDoor, a new Linux backdoor associated with UAT-7810, and a variant of ShortLeash, as well as router forensics techniques for hunting these threats on compromised routers and malware analysis tools used in our investigation. CJDoor targets the MIPS architecture and is designed to configure compromised devices as part of an attacker-controlled communications infrastructure. Through reverse engineering of the CJDoor binary and its associated kernel components, we identified its internal architecture, command protocol, and cryptographic operations. CJDoor employs a communications architecture that differs from those used by conventional Linux backdoors. This presentation examines the design and internal implementation of its command-and-control communications, which are built on an encrypted overlay network. In particular, we explain how CJDoor configures cjdns on a compromised router, connects the device to an attacker-operated cjdns network, and enables it to function as a node within that network. We describe the initial connection process using remote-node information and authentication credentials, the generation of node keys and IPv6 addresses, and the establishment of encrypted peer-to-peer communications. These findings reveal how compromised devices are incorporated into the attacker’s overlay network. We also discuss how this communications model may affect the effectiveness of conventional detection methods.
In addition to our analysis of CJDoor, we present findings from our investigation of a previously undocumented variant of ShortLeash, malware that has been reported as being used by UAT-7810. We compare this variant with previously known malware associated with UAT-7810 and examine, from a technical perspective, how the group’s ORB infrastructure and capabilities may be evolving.
Based on the knowledge gained through this research, we also introduce methods for detecting and mitigating these threats. Applying conventional endpoint forensic techniques to compromised routers can be difficult. We therefore discuss a forensic approach that uses UART to establish hardware-level access and extract device images. We demonstrate how this method can support investigations and explain practical measures for identifying router compromise, conducting initial incident response, and mitigating related threats. We will also release a C++-based tool developed to support malware analysis.
Through this presentation, attendees will gain an understanding of the internal architecture of CJDoor and the ShortLeash variant associated with UAT-7810. They will also learn how compromised routers join an attacker-controlled cjdns network and operate as nodes within ORB infrastructure. In addition, attendees will gain technical insights that can support malware analysis, detection, defense, forensic investigation, and incident response.

Yuma Masubuchi – JPCERT/CC
Yuma Masubuchi is a Malware Analyst and Intelligence Analyst in the Cyber Security Coordination Group at JPCERT/CC. He investigates APT-related incidents, analyzes malware. His research covers targeted attacks against Windows, Linux, network appliances, and edge devices. He has presented his work at international cybersecurity conferences, including CODE BLUE and AVAR. He also serves as a trainer for the JSAC, sharing practical techniques for malware analysis, threat intelligence, and incident investigation. JPCERT/CC publishes technical research, analysis tools, and other resources through its official blog and GitHub repositories.