TF-MAL-elf.polaredge
📛 Threat Title
Malware family: PolarEdge
Description
ThreatFox malware family `elf.polaredge`. Printable name: PolarEdge.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.polaredge
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.polaredge
IOC database
- Type
- domain
- Value
elf.polaredge- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.polaredge
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.polaredge
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.sekoia.io
Discover PolarEdge , a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.
-
web:cyberpress.org
Security researchers at XLab have uncovered a massive expansion of the PolarEdge botnet infrastructure, revealing more than 25,000 compromised devices and 140 command-and-control servers operating across 40 countries.
-
web:cybersecurefox.com
If PolarEdge's activity began in mid-2023, some devices may have endured long-term compromise, raising risks of covert lateral movement, bandwidth abuse, and reputational damage for organizations unwittingly relaying malicious traffic. Detection and mitigation : steps for Cisco, ASUS, QNAP and Synology administrators
-
web:cybersecuritynews.com
A sophisticated botnet campaign has compromised more than 25,000 IoT devices across 40 countries while establishing 140 command-and-control servers to facilitate cybercrime operations. The PolarEdge botnet, first disclosed in February 2025, exploits vulnerable IoT and edge devices to construct an Operational Relay Box network that provides infrastructure-as-a-service for advanced persistent ...
-
web:hivepro.com
Attack Details #1 A newly identified malware campaign is actively targeting edge devices from Cisco, ASUS, QNAP, and Synology, enlisting them into a botnet known as PolarEdge . The attackers exploit CVE-2023-20118, a vulnerability that enables remote command execution (RCE). By leveraging this flaw, they deploy a web shell onto compromised routers, ultimately infecting them with an undocumented ...
-
web:lorikeetsecurity.com
A new TLS‑based ELF implant, PolarEdge , is compromising Cisco routers, ASUS and QNAP NAS, and Synology devices. It leverages CVE‑2023‑20118, creates SOCKS5 proxies, and evades detection with anti‑analysis tricks. Learn the impact, exposure checks, and rapid mitigation steps.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family , but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB ...
-
web:news.backbox.org
A new malware campaign has been observed targeting edge devices from Cisco, ASUS, QNAP, and Synology to rope them into a botnet named PolarEdge since at least the end of 2023.
-
web:thehackernews.com
Cybersecurity researchers have shed light on the inner workings of a botnet malware called PolarEdge . PolarEdge was first documented by Sekoia in February 2025, attributing it to a campaign targeting routers from Cisco, ASUS, QNAP, and Synology with the goal of corralling them into a network for an as-yet-undetermined purpose.
-
web:www.censys.com
UPDATE 9/24/2025: Clarifications on Our PolarEdge Research We were recently informed by a community member that the certificate highlighted in earlier versions of this research is also present in older versions of Mbed TLS, version 3.4.0, previously known as PolarSSL. Additionally, the TLS certificate we had associated with the " PolarEdge " malware also originates from the same Mbed TLS ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.