Target Industry
Telecoms, security and IT, specifically vulnerable CCTV, routers and other edge/IoT devices (concentrated in North America, South Korea, China and Thailand).
Overview
The PolarEdge Botnet is a recently identified large-scale campaign targeting vulnerable Internet-of-Things (IoT) and network edge devices globally. First disclosed in February 2025, it exploits weaknesses in internet-exposed routers, network-attached storage (NAS) appliances, and virtual private network (VPN) gateways to enrol them into a distributed malicious network.
The botnet has reportedly infected approximately 25,000 devices worldwide, a sharp increase from earlier estimates of just over 2,000. Most affected systems are deployed in small business and residential environments, though some enterprise networks have also been impacted.
Further analysis by cybersecurity researchers indicates that PolarEdge targets products from Cisco (Small Business RV series), ASUS, QNAP, and Synology, exploiting known vulnerabilities, notably CVE-2023-20118 (CVSS Score 7.2), to gain remote code execution. Once compromised, devices establish TLS-encrypted command and control channels and are integrated into a resilient botnet capable of DDoS attacks and proxy relay operations.
Impact
The organisational impact of the PolarEdge Botnet is assessed as high, given the scale of compromise and the critical nature of affected infrastructure. The widespread infection of network edge and IoT devices increases the risk of service instability, network congestion, and operational inefficiencies, particularly where compromised assets underpin connectivity or remote access. The presence of unauthorised processes on exposed devices also weakens security posture, enabling potential lateral movement, data exfiltration, and follow-on compromise.
Exploitation
PolarEdge propagates through a combination of techniques, including credential brute forcing, which involves automated attempts against default or weak administrative passwords on routers and VPN devices. It also exploits vulnerabilities in outdated or misconfigured firmware, particularly affecting under-maintained Small Office/Home Office (SOHO) and Small and Medium-sized Business (SMB) devices.
Once compromised, the device establishes encrypted command and control (C2) channels to maintain access and receive instructions. Post infection scripts enable lateral movement to neighbouring subnets, increasing botnet density within local networks. Compromised systems communicate with rotating IPs and domain infrastructure to evade takedown efforts, reflecting a mature command architecture.
Containment, Mitigations & Remediations
It is highly recommended to take the following actions to reduce exposure and impact:
- Credential Hardening: Implement strong administrative passwords and disable remote access features unless strictly required.
- Patch Management: Apply the latest firmware updates from device vendors and monitor advisories for emerging CVEs.
- Network Segmentation: Isolate management interfaces from internet exposure and restrict access to trusted IPs.
- Anomaly Detection: Deploy network monitoring for unusual outbound traffic or abnormal resource utilisation on edge devices.
Threat Landscape
The PolarEdge Botnet underscores the shifting adversarial focus towards network edge infrastructure, devices often overlooked in patch cycles and lacking endpoint telemetry. The campaign reflects an evolution of IoT and router-based botnets, combining classical DDoS tooling with stealthier persistence and C2 evasion tactics.
Given its global footprint (United States, United Kingdom, Germany, France, Japan, India, Brazil, Taiwan, Russia, and others), PolarEdge likely serves as a rental DDoS as a Service platform for criminal clients. The prevalence of infected business class routers suggests both opportunistic scanning and targeted exploitation of organisations with high bandwidth connections.
Threat Group
Attribution remains inconclusive, but infrastructure patterns overlap with known Mirai-lineage botnets and past operations associated with the Moobot and DemonBot families. Current assessment points to a financially motivated actor or criminal consortium rather than state-sponsored activity.
The operators exhibit advanced operational security (rotating C2 infrastructure, obfuscated payloads, anti-analysis techniques) and have demonstrated continued development, implying an established threat group maintaining an active botnet-as-a-service ecosystem.
Further Information
PolarEdge Botnet Infected 25,000+ Devices and 140 C2 Servers Exploiting IoT Vulnerabilities
Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Vulnerabilities
Intelligence Terminology Yardstick













