Target Industry

Telecoms, security and IT, specifically vulnerable CCTV, routers and other edge/IoT devices (concentrated in North America, South Korea, China and Thailand).

Overview

The PolarEdge Botnet is a recently identified large-scale campaign targeting vulnerable Internet-of-Things (IoT) and network edge devices globally. First disclosed in February 2025, it exploits weaknesses in internet-exposed routers, network-attached storage (NAS) appliances, and virtual private network (VPN) gateways to enrol them into a distributed malicious network.

The botnet has reportedly infected approximately 25,000 devices worldwide, a sharp increase from earlier estimates of just over 2,000. Most affected systems are deployed in small business and residential environments, though some enterprise networks have also been impacted.

Further analysis by cybersecurity researchers indicates that PolarEdge targets products from Cisco (Small Business RV series), ASUS, QNAP, and Synology, exploiting known vulnerabilities, notably CVE-2023-20118 (CVSS Score 7.2), to gain remote code execution. Once compromised, devices establish TLS-encrypted command and control channels and are integrated into a resilient botnet capable of DDoS attacks and proxy relay operations.

Impact

The organisational impact of the PolarEdge Botnet is assessed as high, given the scale of compromise and the critical nature of affected infrastructure. The widespread infection of network edge and IoT devices increases the risk of service instability, network congestion, and operational inefficiencies, particularly where compromised assets underpin connectivity or remote access. The presence of unauthorised processes on exposed devices also weakens security posture, enabling potential lateral movement, data exfiltration, and follow-on compromise.

Exploitation

PolarEdge propagates through a combination of techniques, including credential brute forcing, which involves automated attempts against default or weak administrative passwords on routers and VPN devices. It also exploits vulnerabilities in outdated or misconfigured firmware, particularly affecting under-maintained Small Office/Home Office (SOHO) and Small and Medium-sized Business (SMB) devices.

Once compromised, the device establishes encrypted command and control (C2) channels to maintain access and receive instructions. Post infection scripts enable lateral movement to neighbouring subnets, increasing botnet density within local networks. Compromised systems communicate with rotating IPs and domain infrastructure to evade takedown efforts, reflecting a mature command architecture.

Containment, Mitigations & Remediations

It is highly recommended to take the following actions to reduce exposure and impact:

  • Credential Hardening: Implement strong administrative passwords and disable remote access features unless strictly required.
  • Patch Management: Apply the latest firmware updates from device vendors and monitor advisories for emerging CVEs.
  • Network Segmentation: Isolate management interfaces from internet exposure and restrict access to trusted IPs.
  • Anomaly Detection: Deploy network monitoring for unusual outbound traffic or abnormal resource utilisation on edge devices.

Threat Landscape

The PolarEdge Botnet underscores the shifting adversarial focus towards network edge infrastructure, devices often overlooked in patch cycles and lacking endpoint telemetry. The campaign reflects an evolution of IoT and router-based botnets, combining classical DDoS tooling with stealthier persistence and C2 evasion tactics.

Given its global footprint (United States, United Kingdom, Germany, France, Japan, India, Brazil, Taiwan, Russia, and others), PolarEdge likely serves as a rental DDoS as a Service platform for criminal clients. The prevalence of infected business class routers suggests both opportunistic scanning and targeted exploitation of organisations with high bandwidth connections.

Threat Group

Attribution remains inconclusive, but infrastructure patterns overlap with known Mirai-lineage botnets and past operations associated with the Moobot and DemonBot families. Current assessment points to a financially motivated actor or criminal consortium rather than state-sponsored activity.

The operators exhibit advanced operational security (rotating C2 infrastructure, obfuscated payloads, anti-analysis techniques) and have demonstrated continued development, implying an established threat group maintaining an active botnet-as-a-service ecosystem.

Further Information

PolarEdge Botnet Infected 25,000+ Devices and 140 C2 Servers Exploiting IoT Vulnerabilities

Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Vulnerabilities

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content