PULSE NAME
Smoking Gun Uncovered: RPX Relay at PolarEdge's Core Exposed
WHITE PolarEdge AlienVault 2025-10-29 Modified: 2025-10-29
13
IOCs
MEDIUM VOLUME
A new component of PolarEdge's infrastructure, RPX_Client, has been discovered, revealing insights into the threat actor's relay operations. The investigation uncovered 140 VPS nodes acting as RPX Servers and over 25,000 infected devices serving as RPX Clients. The system uses a multi-hop design to conceal attack sources, with compromised IoT devices and VPS servers forming robust barriers. RPX_Client functions as a jumpserver in the Operational Relay Box (ORB) network, providing proxy services and enabling remote command execution. The analysis also revealed connections between previously known PolarEdge infrastructure and the newly discovered components, confirming the attribution to this threat actor.
Indicators of Compromise (13)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1fb2dfb09a31f0e8c63cc83283532f06 2025-10-29
FileHash-MD5 3e5e99b77012206d4d4469e84c767e6b 2025-10-29
FileHash-MD5 571088182ed7e33d986b3aa2c51efd27 2025-10-29
FileHash-MD5 7fa5fb15098efdf76e4c016e2e17bb38 2025-10-29
FileHash-MD5 96b3be4cf3ad232ca456f343f468da0e 2025-10-29
FileHash-SHA1 2c0184a1eb37fe0c26a76b96466d6ba44028632f 2025-10-29
FileHash-SHA256 3f00058448b8f7e9a296d0cdf6567ceb23895345eae39d472350a27b24efe999 2025-10-29
FileHash-SHA256 827797a9bff728ae6f46abd505e67a15e40b0ba69a8dc92a36fd90d9974c9593 2025-10-29
FileHash-SHA256 e234e102cd8de90e258906d253157aeb7699a3c6df0c4e79e05d01801999dcb5 2025-10-29
domain beastdositadvtofm.site 2025-10-29
domain centrequ.cc 2025-10-29
domain icecreand.cc 2025-10-29
hostname blog.sekoia.io 2025-10-29