s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.polaredge

📛 Threat Title

Malware family: PolarEdge

Category: PolarEdge First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.polaredge`. Printable name: PolarEdge.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.polaredge VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.polaredge

IOC database

Type
domain
Value
elf.polaredge
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.polaredge

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.polaredge

References (1)

Remediations (10)

  • web:blog.sekoia.io

    Discover PolarEdge , a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

  • web:cyberpress.org

    Security researchers at XLab have uncovered a massive expansion of the PolarEdge botnet infrastructure, revealing more than 25,000 compromised devices and 140 command-and-control servers operating across 40 countries.

  • web:cybersecurefox.com

    If PolarEdge's activity began in mid-2023, some devices may have endured long-term compromise, raising risks of covert lateral movement, bandwidth abuse, and reputational damage for organizations unwittingly relaying malicious traffic. Detection and mitigation : steps for Cisco, ASUS, QNAP and Synology administrators

  • web:cybersecuritynews.com

    A sophisticated botnet campaign has compromised more than 25,000 IoT devices across 40 countries while establishing 140 command-and-control servers to facilitate cybercrime operations. The PolarEdge botnet, first disclosed in February 2025, exploits vulnerable IoT and edge devices to construct an Operational Relay Box network that provides infrastructure-as-a-service for advanced persistent ...

  • web:hivepro.com

    Attack Details #1 A newly identified malware campaign is actively targeting edge devices from Cisco, ASUS, QNAP, and Synology, enlisting them into a botnet known as PolarEdge . The attackers exploit CVE-2023-20118, a vulnerability that enables remote command execution (RCE). By leveraging this flaw, they deploy a web shell onto compromised routers, ultimately infecting them with an undocumented ...

  • web:lorikeetsecurity.com

    A new TLS‑based ELF implant, PolarEdge , is compromising Cisco routers, ASUS and QNAP NAS, and Synology devices. It leverages CVE‑2023‑20118, creates SOCKS5 proxies, and evades detection with anti‑analysis tricks. Learn the impact, exposure checks, and rapid mitigation steps.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family , but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB ...

  • web:news.backbox.org

    A new malware campaign has been observed targeting edge devices from Cisco, ASUS, QNAP, and Synology to rope them into a botnet named PolarEdge since at least the end of 2023.

  • web:thehackernews.com

    Cybersecurity researchers have shed light on the inner workings of a botnet malware called PolarEdge . PolarEdge was first documented by Sekoia in February 2025, attributing it to a campaign targeting routers from Cisco, ASUS, QNAP, and Synology with the goal of corralling them into a network for an as-yet-undetermined purpose.

  • web:www.censys.com

    UPDATE 9/24/2025: Clarifications on Our PolarEdge Research We were recently informed by a community member that the certificate highlighted in earlier versions of this research is also present in older versions of Mbed TLS, version 3.4.0, previously known as PolarSSL. Additionally, the TLS certificate we had associated with the " PolarEdge " malware also originates from the same Mbed TLS ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.