⤷ Title: Sekoia Exposes PolarEdge Backdoor: Custom mbedTLS C2 Compromising Cisco, QNAP, and Synology Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 00:11:51 +0000
════════════════════════
⌗ Tags: #Malware #Arbitrary Command Execution #backdoor #cisco #Custom C2 #IOT #mbedTLS #PolarEdge #QNAP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 00:11:51 +0000
════════════════════════
⌗ Tags: #Malware #Arbitrary Command Execution #backdoor #cisco #Custom C2 #IOT #mbedTLS #PolarEdge #QNAP
Daily CyberSecurity
Sekoia Exposes PolarEdge Backdoor: Custom mbedTLS C2 Compromising Cisco, QNAP, and Synology Devices
Sekoia details PolarEdge, a Rust-based backdoor using a custom mbedTLS server for C2 on Cisco, QNAP, and Synology devices. The backdoor uses XOR 0x11 for config obfuscation and attempts to delete system utilities to block rivals.