216.73.217.22

Smoking Gun Uncovered: RPX Relay at PolarEdge's Core Exposed

· Published 29/10/2025 18:37 · Modified 29/10/2025 20:20

Export JSON

Essential information

Published
29/10/2025 18:37
Modified
29/10/2025 20:20
Tags
2025-10-29 CVE-2023-20118 botnet command execution evasion infrastructure iot orb polaredge proxy rpx_client rpx_server vps
Related entities
7 observables, 1 intrusion sets (apt), 11 techniques (mitre), 9 others

Description

A new component of 's , , has been discovered, revealing insights into the threat actor's relay operations. The investigation uncovered 140 nodes acting as RPX Servers and over 25,000 infected devices serving as RPX Clients. The system uses a multi-hop design to conceal attack sources, with compromised devices and servers forming robust barriers. functions as a jumpserver in the Operational Relay Box () network, providing services and enabling remote . The analysis also revealed connections between previously known and the newly discovered components, confirming the attribution to this threat actor.

External references