PolarEdge
PolarEdge is an Operational Relay Box (ORB) / botnet-style threat cluster active since at least late 2023 that compromises vulnerable routers, NAS, and other IoT/edge devices to build relay and proxy infrastructure. It has been described as exploiting CVE-2023-20118 for initial access and deploying a TLS backdoor referred to as "cipher_log." Reported victim device types and brands include Cisco and ASUS routers, QNAP and Synology NAS devices, and additional device families identified in later reporting such as KT CCTV, TVT DVR, Cyberoam UTM, DrayTek, D-Link, Cisco RV340, and Uniview devices. Reporting from Sekoia, Censys, and XLab describes PolarEdge as using compromised IoT/edge devices together with purchased VPS infrastructure to form an ORB network that provides proxying, relay capability, and remote command execution. XLab attributes a previously undocumented component, RPX_Client, to PolarEdge and describes it as onboarding compromised devices into a proxy pool, registering to RPX_Server infrastructure on port 55555, and connecting to a Go-Admin service on port 55560 for remote command execution, including C2 migration and self-update. RPX_Client reportedly persists by modifying init scripts, stores configuration in an XOR-obfuscated file, and disguises its process name as "connect_server." RPX_Server nodes were reported to be concentrated on Alibaba Cloud and Tencent Cloud VPS infrastructure. The cluster has been associated with consistent PolarSSL-branded or PolarSSL test TLS certificates and ORB-like infrastructure patterns. XLab reported identifying 140 active RPX_Server nodes and datasets indicating more than 25,000 cumulatively infected device IPs since July 2024 across 40 countries/regions, while other reporting states infections grew from roughly 2,000 devices to more than 40,000 devices. Infections were reported as concentrated in Southeast Asia and North America, with notable shares in South Korea, China, Thailand, Malaysia, India, Israel, the United States, Vietnam, Indonesia, and Russia. PolarEdge has been discussed alongside other router-targeting ORB networks such as LapDogs, but the content states they are separate entities despite some similarities. Multiple sources note that PolarEdge shows ORB-like traits and patterns similar to networks linked to Chinese espionage campaigns, and some content explicitly describes PolarEdge as China-linked; however, attribution confidence varies across reporting. Known aliases directly provided in the content are limited to PolarEdge / polaredge. Related components and infrastructure mentioned in the content include cipher_log, RPX_Client, RPX_Server, downloader "w," and script "q."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- critical-infrastructure
- technology
- telecommunications
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ORB activity cluster reported as targeting routers in recent months (no further details provided in the content).
Operates an ORB-style proxy/relay infrastructure by compromising IoT/edge devices (e.g., CCTV/DVRs, routers, UTMs) and integrating them into a managed proxy pool (RPX_Client) controlled by VPS-based gateways (RPX_Server) and management tooling (Go-Admin/Nginx/Go-Shadowsocks). Provides proxy services (SOCKS5/SOCKS5-over-TLS/Trojan) and remote command execution to manage/rotate nodes and C2, enabling traffic obfuscation and source hiding for downstream operations.
PolarEdge is a botnet infecting routers and NAS devices, showing traits similar to Chinese espionage-linked ORB networks.
A separate activity cluster (distinct from LapDogs) that exploits known router/IoT vulnerabilities to build a compromised-device network since late 2023; uses a backdoor that replaces device CGI scripts with an operator-designated webshell.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.