PolarEdge: Unveiling an uncovered ORB network
ID: 37ea2d36-5b2f-5b9c-9d22-7465fc934cf5
STIX ID: report--37ea2d36-5b2f-5b9c-9d22-7465fc934cf5
Feed Name: Sekoia.com
Threat Score
This report documents active exploitation of CVE-2023-20118 to deploy a TLS backdoor family dubbed PolarEdge that compromises edge devices (Cisco, Asus, QNAP, Synology). Sekoia observed webshell deployments and a MIPS64 ELF backdoor (cipher_log) forming a botnet of ~2,017 infected devices that report to attacker-controlled domains/IPs; the report provides payload analysis, delivery and reporting infrastructure details, and IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
