RPX_Client is a previously undocumented malware component that XLab linked with high confidence to the PolarEdge IoT/edge Operational Relay Box (ORB) network. XLab describes it as the first confirmed relay-node malware for PolarEdge, used to onboard compromised devices into the proxy pool of designated C2 nodes, provide proxy/relay services, and enable remote command execution. The broader PolarEdge operation is described as exploiting vulnerable IoT and edge devices while using purchased VPS infrastructure running RPX_Server nodes.
Observed delivery included an ELF downloader named "w" distributed from 111.119.223.196 on May 30, 2025, and a captured "script q" on June 2, 2025 that delivered rpx_client. XLab also reported an earlier December 2023 chain of script a -> ELF w -> script q. The activity is additionally associated with exploitation of CVE-2023-20118 from 111.119.223.196 on April 27, 2025 to spread a script named "s". Attribution to PolarEdge is supported in the content by script and ELF coding-style similarity to known PolarEdge samples, RPX_Server database records showing RPX_Client distribution via 111.119.223.196, functional complementarity with RPX_Server, and infrastructure overlap involving 82.118.22.155 and beastdositadvtofm[.]site, both reportedly present in a decrypted PolarEdge backdoor configuration tied to sample hash 3e5e99b77012206d4d4469e84c767e6b.
For persistence, rpx.sh appends "/bin/sh /mnt/mtd/rpx.sh &" to /etc/init.d/rcS. RPX_Client disguises its process name as "connect_server", enforces single-instance execution via /tmp/.msc, and stores configuration in .fccq obfuscated with single-byte XOR 0x25. It connects to RPX_Server on a configured port, commonly 55555, for registration and proxying, and to port 55560, identified as a Go-Admin service, for remote command execution. Reported remote commands include change_pub_ip and update_vps, enabling functions such as C2 migration and self-update. XLab also states RPX_Server-side APIs can export proxy pool nodes into Clash configuration files.
The infrastructure described in the content includes RPX_Server nodes typically running RPX_Server, Nginx, Go-Admin, and Go-Shadowsocks, with Nginx reverse proxying port 19999 to Go-Admin. XLab identified 140 active RPX_Server nodes using a fingerprint of a PolarSSL test certificate on port 55555 and protocol validation, with nodes concentrated on Alibaba Cloud and Tencent Cloud. XLab reports datasets indicating more than 25,000 cumulatively infected device IPs since July 2024 across 40 countries/regions, primarily in Southeast Asia and North America. The top affected countries by share were reported as South Korea, China, Thailand, Malaysia, India, Israel, the United States, Vietnam, Indonesia, and Russia. Device groupings in the dataset indicate heavy impact on KT CCTV and Shenzhen TVT DVR devices, with additional affected device types including Cyberoam UTM, Asus routers, DrayTek routers, Cisco RV340 VPN routers, D-Link routers, and Uniview webcams.
High-confidence indicators and artifacts directly mentioned in the content include: IPs 111.119.223.196 and 82.118.22.155; domain beastdositadvtofm[.]site; files/scripts "w", "q", "a", "s", wget.tar, rpx, and rpx.sh; persistence path /etc/init.d/rcS; mutex/lock file /tmp/.msc; config file .fccq; process name "connect_server"; ports 55555, 55560, and 19999; and remote command strings change_pub_ip and update_vps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named component described as a relay node within the PolarEdge IoT ORB network, likely used to proxy/relay traffic as part of an operational relay box (ORB) infrastructure.
RPX_Client is the compromised-device component of PolarEdge’s RPX relay system. It persists via init script modification, stores an XOR-obfuscated local config (.fccq), registers to RPX_Server for proxying (port 55555), and maintains a second channel to Go-Admin (port 55560) for UUID-authenticated remote command execution (including C2 migration and self-update).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.