PolarEdge Backdoor on QNAP: CVE-2023-20118 Analysis
ID: 576e6369-3c2f-5662-9e08-8ff6e56cc16a
STIX ID: report--576e6369-3c2f-5662-9e08-8ff6e56cc16a
Feed Name: Sekoia.com
This report analyzes the PolarEdge Backdoor, a TLS-based implant observed in early 2025 deployed via exploitation of CVE-2023-20118 against routers and QNAP/Asus/Synology NAS devices. The backdoor runs a built-in mbedTLS server with an unauthenticated custom binary protocol that permits arbitrary command execution, periodically fingerprints infected hosts to C2 servers (and can download/execute payloads), supports connect-back and debug modes for remote updates, and employs multiple anti-analysis techniques (process masquerading, /proc remounting, chained PRESENT cipher, simple XOR/affine obfuscation). The report includes a full technical breakdown of configuration parsing, certificates, protocol tokens, persistence/watchdog behavior, example commands, a YARA rule, and the analyzed sample hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
