PolarEdge has compromised internet-facing devices from Cisco, ASUS, QNAP, and Synology, creating a covert botnet whose operators and ultimate purpose remain unknown. HivePro reports more than 2,000 infections worldwide and activity dating to late 2023. Sekoia first detected the botnet in January 2025 through attacks exploiting CVE-2023-20118 on Cisco routers, then identified related backdoor samples targeting other vendors. That exploitation finding does not establish that the same vulnerability affects the QNAP, ASUS, or Synology devices.
Sekoia’s analysis of a QNAP NAS implant found a TLS server that accepts arbitrary commands and a separate channel that sends daily host fingerprints to command-and-control infrastructure and can download and execute additional payloads. The custom command protocol has no additional authentication beyond extractable magic tokens. Encrypted configuration and code sections, process masquerading, concealment of process information, and a watchdog complicate detection, but do not substantiate claims that the backdoor is undetectable. The analyzed implant does not itself persist across reboots; auxiliary modes support TLS file retrieval and C2 address updates. Defenders should prioritize patching affected Cisco routers, restricting internet exposure of device-management interfaces, and investigating unexpected TLS listeners, outbound beaconing, and suspicious processes on edge devices and NAS systems.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Sekoia originally distributed its PolarEdge technical analysis as a private FLINT report. The analysis described a QNAP implant supporting arbitrary command execution over TLS, daily host fingerprinting, additional payload execution, and process-concealment mechanisms, but no built-in persistence across reboots.
Sekoia provided a PolarEdgeBackdoor YARA rule dated July 10, 2025. It detects ELF files smaller than 2 MB using the PRESENT inverse S-box alongside configuration markers or characteristic command-line strings.
Cisco-router honeypots detected simultaneous exploitation of CVE-2023-20118 from multiple IP addresses in different countries. Attackers retrieved a shell script named q over FTP, which downloaded and launched the PolarEdge backdoor.
Researchers first detected PolarEdge when honeypots observed attackers exploiting CVE-2023-20118 on Cisco routers. The exploitation achieved remote code execution and deployed a web shell.
PolarEdge reportedly began operating in late 2023, compromising internet-connected devices and installing backdoors.
Researchers identified related PolarEdge backdoor payloads targeting Asus, QNAP, and Synology devices, extending the observed targeting beyond Cisco routers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.