Smoking Gun Uncovered: RPX Relay at PolarEdge’s Core Exposed
ID: 03534aea-e4e5-5a1c-9b2f-2ea135413d4a
STIX ID: report--03534aea-e4e5-5a1c-9b2f-2ea135413d4a
Feed Name: QiAnXin XLab
XLab uncovered and analyzed PolarEdge’s RPX relay system: a malware-driven ORB network that recruits compromised IoT/edge devices (25,000+ infected devices) and VPS nodes (140 RPX servers) to provide stealthy proxy services and remote command execution. The report details captured samples (RPX_Client and RPX_Server), distribution scripts (w, q), exploitation activity tied to CVE-2023-20118 and downloader IPs, network protocols/ports (notably 55555 and 55560), certificate fingerprints, runtime config formats, operational commands (e.g., change_pub_ip, update_vps), and a list of IOCs to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
