PolarEdge: Unveiling an uncovered ORB network
ID: 425689d1-2000-5c47-a0a2-7467ebdb517a
STIX ID: report--425689d1-2000-5c47-a0a2-7467ebdb517a
Feed Name: Sekoia.io Blog
Date Published: 2025-02-25
Date Updated: 2026-04-29
Author: Jeremy Scion, Felix Aimé and Sekoia TDR
Sekoia TDR observed active exploitation of CVE-2023-20118 against Cisco Small Business routers to deploy a multi-platform botnet family dubbed "PolarEdge"; analysis reveals a MIPS64 TLS backdoor (cipher_log) using Mbed TLS/PolarSSL certificates, multiple X86_64 payloads targeting Asus/QNAP/Synology, extensive C2/reporting infrastructure, and over 2,000 compromised edge devices with associated IoCs and domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
