logo

Defrosting PolarEdge’s Backdoor

ID: 8f20cfb6-1114-5c48-8027-453dbaba8d9f

STIX ID: report--8f20cfb6-1114-5c48-8027-453dbaba8d9f

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2025-10-14

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

This report presents an in-depth reverse-engineering analysis of the PolarEdge Backdoor (SHA256: a3e2826090f009691442ff1585d07118c73c95e40088c47f0a16c8a59c9d9082), a TLS-based implant deployed after exploitation of CVE-2023-20118 against QNAP (and other vendor) devices; it documents configuration storage, a custom binary protocol for unauthenticated command execution, fingerprinting/connect-back/debug modes, anti-analysis measures, and supplies IoCs and a YARA detection rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.