A Look at PolarEdge Adjacent Infrastructure
ID: 3a9708a7-ab0e-5472-bee2-6e5b523ad9f5
STIX ID: report--3a9708a7-ab0e-5472-bee2-6e5b523ad9f5
Feed Name: Censys Blog
Date Published: 2025-09-23
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
Censys researchers investigated PolarEdge, an IoT botnet exploiting CVE-2023-20118, and discovered an RPX reverse-connect proxy server (binary SHA256: 827797a9...) that manages proxy nodes (ORBs) and exposes SOCKS5/TLS/Trojan services. The RPX server orchestrates reverse connections from compromised devices, bridges client traffic to chosen proxy nodes, uses simple XOR/DES obfuscation, and was found alongside reused Mbed TLS test certificates and multiple hosts and logs; several IOCs (IPs, cert fingerprints, and binary hash) are provided, though certificate overlap tempers direct attribution to PolarEdge.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
