logo

PolarEdge Backdoor on QNAP: CVE-2023-20118 Analysis

ID: 576e6369-3c2f-5662-9e08-8ff6e56cc16a

STIX ID: report--576e6369-3c2f-5662-9e08-8ff6e56cc16a

Feed Name: Sekoia.com

Threat Score
78/100

Date Published: 2025-10-14

Date Updated: 2026-07-20

...
...

This report analyzes the PolarEdge Backdoor, a TLS-based implant observed in early 2025 deployed via exploitation of CVE-2023-20118 against routers and QNAP/Asus/Synology NAS devices. The backdoor runs a built-in mbedTLS server with an unauthenticated custom binary protocol that permits arbitrary command execution, periodically fingerprints infected hosts to C2 servers (and can download/execute payloads), supports connect-back and debug modes for remote updates, and employs multiple anti-analysis techniques (process masquerading, /proc remounting, chained PRESENT cipher, simple XOR/affine obfuscation). The report includes a full technical breakdown of configuration parsing, certificates, protocol tokens, persistence/watchdog behavior, example commands, a YARA rule, and the analyzed sample hash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.