PolarEdge
- Malware type
- backdoor
- Family
- Malware family
- Last IoC activity
- 2026-07-21 16:37:47
- Profile updated
- 2026-07-07 14:28:38
Targeted industries: technology-and-telecommunications
Context
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family, but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB) to facilitate offensive cyber operations.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Polaredge (report)
- blog.sekoia.io — Polaredge Unveiling An Uncovered Iot Botnet (report)
- censys.com — 2025 State Of The Internet Digging Into Residential Proxy Infrastructure (report)
- blog.xlab.qianxin.com — Smoking Gun Uncovered Rpx Relay At Polaredges Core Exposed (report)