PolarEdge is a suspected China-linked Operational Relay Box (ORB) network active since at least late 2023 that compromises routers, NAS appliances, DVRs, CCTV infrastructure, and other internet-facing IoT or edge devices to build a covert relay and proxy ecosystem. It has been associated with exploitation of CVE-2023-20118 and with malware and backdoor components including cipher_log, RPX_Client, and RPX_Server. The network has been described as combining compromised edge devices with VPS-based relay infrastructure to provide proxying, remote command execution, and operational cover for follow-on intrusion activity. PolarEdge has targeted devices from multiple vendors, including Cisco, ASUS, QNAP, Synology, DrayTek, D-Link, and video-surveillance or DVR ecosystems. Reported infections expanded from a few thousand devices to tens of thousands globally, with concentrations in South Korea, China, Thailand, Malaysia, India, Israel, the United States, Vietnam, Indonesia, and Russia. Observed victim geography and tradecraft indicate broad targeting of edge infrastructure rather than a single vertical, with implications for government, enterprise, telecommunications, and critical-infrastructure environments connected through compromised perimeter devices. Technical reporting links PolarEdge to CGI-script replacement and web-shell-style persistence on infected devices, operation from temporary filesystem locations, use of TLS backdoors, and reuse of consistent PolarSSL-branded certificates on parts of its infrastructure. RPX_Client has been reported to persist through init-script modification, register compromised devices to RPX_Server nodes for proxy tasks, and support remote command execution and self-update. RPX_Server infrastructure has been observed on cloud-hosted VPS nodes and appears to manage registration, session validation, command distribution, and export of proxy-node configurations. PolarEdge shares some infrastructure traits with other ORB ecosystems such as LapDogs but is assessed as a distinct cluster due to differences in malware, persistence, certificate handling, and infection workflow. Multiple assessments note similarities between PolarEdge and broader Chinese espionage-linked ORB activity, and some reporting explicitly characterizes PolarEdge as China-linked with espionage-oriented objectives. High-confidence reporting supports its role as stealth infrastructure for relay, concealment, and persistent access rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ORB activity cluster reported as targeting routers in recent months (no further details provided in the content).
Operates an ORB-style proxy/relay infrastructure by compromising IoT/edge devices (e.g., CCTV/DVRs, routers, UTMs) and integrating them into a managed proxy pool (RPX_Client) controlled by VPS-based gateways (RPX_Server) and management tooling (Go-Admin/Nginx/Go-Shadowsocks). Provides proxy services (SOCKS5/SOCKS5-over-TLS/Trojan) and remote command execution to manage/rotate nodes and C2, enabling traffic obfuscation and source hiding for downstream operations.
PolarEdge is a botnet infecting routers and NAS devices, showing traits similar to Chinese espionage-linked ORB networks.
A separate activity cluster (distinct from LapDogs) that exploits known router/IoT vulnerabilities to build a compromised-device network since late 2023; uses a backdoor that replaces device CGI scripts with an operator-designated webshell.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.