PolarEdge is a TLS-based backdoor associated with a botnet targeting internet-facing routers and network-attached storage devices, including equipment from Cisco, ASUS, QNAP, and Synology. The operation has been active since at least late 2023 and was publicly documented in February 2025. Observed infection chains exploit CVE-2023-20118 in Cisco Small Business routers to execute commands and retrieve shell scripts that download and launch the implant. Associated intrusions also deploy webshells to retain remote access.
PolarEdge uses architecture-specific ELF payloads and the Mbed TLS library, formerly known as PolarSSL, for encrypted communications. It fingerprints infected hosts, receives remote commands through a built-in TLS server, executes those commands, and returns their output. Additional modes support remote file downloads and interactive configuration changes. Defense-evasion features include XOR-obfuscated configuration, process-name masquerading, anti-analysis logic, and removal of selected files. A watchdog child process periodically checks whether the main backdoor remains active and relaunches it if necessary; this mechanism does not itself provide persistence across reboots.
PolarEdge compromises both consumer and enterprise edge equipment worldwide. Its operators and ultimate objectives have not been conclusively established. Public Mbed TLS test certificates used by the malware are not unique to PolarEdge and cannot independently establish infection or infrastructure attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initially, it followed a familiar playbook, exploiting a critical Cisco Small Business router vulnerability (CVE-2023-20118) to implant base64-encoded webshells.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Infected equipment show signs of malware that researchers codenamed PolarEdge..."; "Sekoia codenamed the malware and associated botnet infrastructure they mapped as PolarEdge..."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"It leverages the proprietary AiCloud service with n-day vulnerabilities in order to gain high privileges on End-Of-Life ASUS WRT routers" ... "The attacks likely exploit vulnerabilities tracked as CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, CVE-2023-41348, CVE-2024-12912, and CVE-2025-2492 for proliferation."
While PolarEdge backdoor replaces the CGI script of the devices with the operator’s designated webshell, ShortLeash merely inserts itself into the system directory as a .service file...
Although the backdoor does not ensure persistence across reboots, it calls fork to spawn a child process that, every 30 seconds, checks whether /proc/<parent-pid> still exists. If the directory has disappeared, the child executes a shell command to relaunch the backdoor
Although the backdoor does not ensure persistence across reboots, it calls fork to spawn a child process that, every 30 seconds, checks whether /proc/<parent-pid> still exists. If the directory has disappeared, the child executes a shell command to relaunch the backdoor
Operations of the PolarEdge botnet ... were discovered to either involve functioning as a TLS client for remote file downloads or on-the-fly configuration modifications... Execution of PolarEdge prompts default TLS server functioning to facilitate host fingerprint delivery to the command-and-control server
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison involving IoT proxy operations that turn compromised edge devices into infrastructure for abuse. No operational connection to Cling is stated.
Botnet campaign targeting edge devices (Cisco/ASUS/QNAP/Synology) using exploits (e.g., CVE-2023-20118) to deploy a backdoor and hijack devices.
A covert botnet reportedly compromising routers from Cisco, ASUS, QNAP, and Synology through an unspecified vulnerability and installing backdoors. The content reports more than 2,000 infected systems worldwide and activity since late 2023. Its ultimate purpose remains unknown; the claim that its backdoor is undetectable is not substantiated in the supplied text.
Named ORB campaign targeting routers (no additional technical details provided in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.