A sophisticated malicious backdoor targeting Internet of Things devices has emerged, using advanced communication techniques to maintain persistent access to compromised systems. The PolarEdge backdoor, first detected in January 2025, represents a significant evolution in IoT-focused threats, utilizing a custom TLS server and proprietary binary protocol for command and control operations.
See also: Confucius targets Windows systems with the AnonDoor backdoor

The malware first appeared through the exploitation of CVE-2023-20118, a vulnerability affecting Cisco routers that allows remote code execution. Attackers exploited this vulnerability to deploy web shells on targeted routers, initially creating access points for subsequent payload delivery. The attack chain involves downloading and executing a shell script named 'q' via FTP, which then retrieves and launches the PolarEdge backdoor on compromised systems.
PolarEdge shows remarkable flexibility in its choice of targets, with variants detected specifically targeting Asus, QNAP , and Synology. The sophisticated design of the malware suggests careful development aimed at establishing a long-term presence in network infrastructure components. Its deployment pattern indicates coordinated campaigns originating from multiple IP addresses in different countries, all using identical User-Agent HTTP headers during exploitation attempts.
Sekoia analysts uncovered the malware's complex architecture during a detailed reverse engineering analysis, revealing a 1.6 MB 64-bit ELF executable that uses multiple functions. The backdoor primarily functions as a TLS server that listens for incoming commands while also maintaining communication with the command and control infrastructure through routine fingerprinting operations.
See also: XWorm campaign shifts to fileless malware

The most unique feature of the PolarEdge backdoor lies in its custom implementation of the TLS server built using the mbedTLS v2.8.0. This approach represents a departure from conventional malware communication methods, providing encrypted channels that closely resemble normal network traffic.
The TLS implementation uses multiple certificates, including leaf certificates and CA chains, creating a genuine appearance of an encrypted communication infrastructure. The malware implements a proprietary binary protocol that operates over the TLS connection, using tokens embedded in the data segments of the executable. This protocol requires specific magic values to validate requests, including tokens stored in the malware configuration and others embedded in the binary.
Command execution occurs when incoming requests contain the ASCII character '1' in the HasCommand field , followed by a two-byte pointer and the actual command string. Fingerprint operations run continuously in dedicated threads, collecting comprehensive system information, including local IP addresses, MAC addresses, process IDs, and specific device details.
See also: Fake Microsoft Teams installers distribute Oyster backdoor

This data is transmitted to command and control servers using HTTP GET requests with specific query string formats. The malware constructs these requests using encrypted format strings that are decoded to reveal parameters such as the device brand, model version, and collected system identifiers. The backdoor supports multiple functions beyond the default server function.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
