PolarEdge

Malware type
backdoor
Family
Malware family
Last IoC activity
2026-07-21 16:37:47
Profile updated
2026-07-07 14:28:38

Targeted industries: technology-and-telecommunications

Context

According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family, but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB) to facilitate offensive cyber operations.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Polaredge (report)
  • blog.sekoia.io — Polaredge Unveiling An Uncovered Iot Botnet (report)
  • censys.com — 2025 State Of The Internet Digging Into Residential Proxy Infrastructure (report)
  • blog.xlab.qianxin.com — Smoking Gun Uncovered Rpx Relay At Polaredges Core Exposed (report)

External references