The PolarEdge botnet has been identified as a sophisticated malware campaign targeting network routers from major vendors including Cisco, ASUS, QNAP, and Synology. Security researchers from Sekoia first documented PolarEdge in early 2025, attributing its activity to a campaign that leverages known vulnerabilities in these devices, notably exploiting CVE-2023-20118 in Cisco routers. Attackers use this vulnerability to download a shell script named 'q' via FTP, which subsequently retrieves and executes the PolarEdge backdoor on compromised systems. The malware is implemented as a TLS-based ELF implant, capable of monitoring incoming client connections and executing commands within them. PolarEdge supports two primary modes of operation: a connect-back mode, where it acts as a TLS client to download files from remote servers, and a debug mode, which allows for on-the-fly configuration changes such as updating server information. The configuration data is embedded and obfuscated within the ELF binary, requiring decryption with a specific XOR key. By default, the backdoor operates as a TLS server, sending host fingerprint data to its command-and-control (C2) server and awaiting further instructions. Researchers have observed that PolarEdge does not ensure persistence across device reboots, but it employs a process monitoring technique where a child process checks every 30 seconds if its parent is still running, relaunching the backdoor if necessary. The botnet also incorporates multiple anti-analysis techniques to evade detection and hinder forensic investigation. The infrastructure supporting PolarEdge has been described as resembling an Operational Relay Box (ORB) network, with evidence suggesting the campaign may have begun as early as June 2023. In addition to its core backdoor functionality, PolarEdge has been linked to the transformation of compromised devices into SOCKS5 residential proxies, facilitated by the GhostSocks malware-as-a-service tool. The full scope and objectives of the botnet remain undetermined, but its technical sophistication and ability to compromise a range of popular router brands highlight a significant threat to both enterprise and residential networks. The campaign's use of TLS for both command-and-control and anti-analysis purposes complicates detection and mitigation efforts. Security teams are advised to patch affected devices, monitor for unusual TLS traffic, and review router configurations for signs of compromise. The ongoing analysis by multiple cybersecurity firms underscores the evolving nature of the PolarEdge threat and the need for continued vigilance against router-targeting malware campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By October 2025, researchers detailed PolarEdge's TLS-based ELF backdoor, including host fingerprinting, remote command execution, dynamic configuration changes, file download capability, anti-analysis behavior, and a child-process relaunch mechanism. The analysis also expanded reporting on affected edge devices from Cisco, ASUS, QNAP, and Synology.
In August 2025, Censys described PolarEdge infrastructure and assessed it as consistent with an Operational Relay Box network. The analysis also suggested the campaign's activity may stretch back to mid-2023.
Sekoia first documented PolarEdge in February 2025, observing exploitation of Cisco router vulnerability CVE-2023-20118 to retrieve a shell script over FTP that downloaded and executed the PolarEdge implant. The reporting established PolarEdge as a botnet targeting edge devices including routers and NAS systems.
Synthient reported that GhostSocks was integrated into Lumma Stealer in early 2024. This marked an expansion of the proxy-enablement tooling into another malware ecosystem.
Synthient reported that GhostSocks, a malware-as-a-service tool for turning compromised devices into SOCKS5 residential proxies, was advertised on the XSS forum in October 2023. The tool was later discussed in connection with the broader proxy ecosystem around compromised edge devices.
Censys assessed PolarEdge infrastructure as consistent with an Operational Relay Box network and indicated the activity may date back to June 2023. This is the earliest reported timeframe associated with the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.