logo

PolarEdge: Unveiling an uncovered ORB network

ID: 425689d1-2000-5c47-a0a2-7467ebdb517a

STIX ID: report--425689d1-2000-5c47-a0a2-7467ebdb517a

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2025-02-25

Date Updated: 2026-04-29

Author: Jeremy Scion, Felix Aimé and Sekoia TDR

...
...

Sekoia TDR observed active exploitation of CVE-2023-20118 against Cisco Small Business routers to deploy a multi-platform botnet family dubbed "PolarEdge"; analysis reveals a MIPS64 TLS backdoor (cipher_log) using Mbed TLS/PolarSSL certificates, multiple X86_64 payloads targeting Asus/QNAP/Synology, extensive C2/reporting infrastructure, and over 2,000 compromised edge devices with associated IoCs and domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.