HomeSecurityPolarEdge botnet infected over 25,000 IoT devices

PolarEdge botnet infected over 25,000 IoT devices

A sophisticated PolarEdge botnet has compromised more than 25,000 IoT devices in 40 countries, while creating 140 command and control servers to facilitate cybercriminal activities.

PolarEdge botnet

The PolarEdge botnet, first discovered in February 2025, exploits vulnerable IoT and edge devices to build an Operational Relay Box that provides infrastructure-as-a-service for advanced threat actors.

The malware operates through a client-server architecture, with RPX_Client components installed on compromised devices and RPX_Server nodes managing proxy services across multiple cloud platforms.

See also: RondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

The botnet campaign began gaining traction in May 2025, when security monitoring systems detected suspicious activity from the IP address 111.119.223.196 distributing an ELF file that had been flagged as related to PolarEdge.

Through analysis, researchers uncovered the RPX_Client component , which integrates compromised devices into designated C2 node proxy pools, while allowing remote command execution . Qianxin researchers identified the malware after targeted research following detection by XLab's Cyber ​​Threat Insight and Analysis System.

The successive discoveries of the RPX_Server and RPX_Client allowed for a deeper understanding of the botnet's relay operations and the scale of its infrastructure. The main targets include KT CCTV systems, Shenzhen TVT DVRs, Cyberoam UTM devices , and various router models from manufacturers such as Asus, DrayTek, Cisco, and D-Link.

PolarEdge botnet infected over 25,000 IoT devices

The botnet infrastructure operates on VPS nodes clustered in autonomous system numbers 45102, 37963, and 132203, hosted primarily on the Alibaba Cloud and Tencent Cloud platforms.

Geographic distribution analysis reveals a concentration of infections in Southeast Asia and North America, with South Korea accounting for 41.97% of compromised devices, followed by China (20.35%) and Thailand (8.37%).

PolarEdge botnet: Technical architecture and infection mechanism

The RPX system implements a multi-hop proxy architecture, designed for source concealment and performance difficulty. When attackers use the network, connections pass from the local proxy through the RPX_Server to the RPX_Client on compromised devices, before reaching their final destinations. This multi-layered approach effectively conceals attack sources while providing operational flexibility.

See also: New Loader-as-a-Service Botnet Targets Routers and IoT Devices

The malware achieves persistence through injection into initialization scripts. Upon execution, RPX_Client changes its process name to connect_server and enforces single-instance execution using the PID file /tmp/.msc to prevent double starts.

The malware attempts to read the global configuration file .fccq to obtain parameters such as C2 server address, communication port, device UUID, and brand information.

Configuration data is single-byte XOR encrypted before storage. Network operations use two independent connections: port 55555 for node registration and traffic proxying, and port 55560 for remote command execution via the go-admin service.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: ShadowV2 Botnet Exploits Docker Containers on AWS

PolarEdge botnet infected over 25,000 IoT devices

The command structure allows flexible control via magic field values ​​0x11, 0x12 and 0x16 that define the bot's functions. Special built-in commands include change_pub_ip for updating C2 server addresses and update_vps for sample self-upgrade capabilities.

Server logs confirm the execution of infrastructure migration commands, demonstrating the ability of operators to quickly move proxy pools when nodes are exposed. Traffic analysis reveals untargeted operations directed primarily at mainstream platforms such as QQ, WeChat, Google, and Cloudflare services.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS