PULSE NAME
Smoking Gun Uncovered: RPX Relay at PolarEdge's Core Exposed
WHITE PolarEdge AlienVault 2025-10-29 Modified: 2025-10-29
13
IOCs
MEDIUM VOLUME
A new component of PolarEdge's infrastructure, RPX_Client, has been discovered, revealing insights into the threat actor's relay operations. The investigation uncovered 140 VPS nodes acting as RPX Servers and over 25,000 infected devices serving as RPX Clients. The system uses a multi-hop design to conceal attack sources, with compromised IoT devices and VPS servers forming robust barriers. RPX_Client functions as a jumpserver in the Operational Relay Box (ORB) network, providing proxy services and enabling remote command execution. The analysis also revealed connections between previously known PolarEdge infrastructure and the newly discovered components, confirming the attribution to this threat actor.
Indicators of Compromise (5 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1fb2dfb09a31f0e8c63cc83283532f06 2025-10-29
FileHash-MD5 3e5e99b77012206d4d4469e84c767e6b 2025-10-29
FileHash-MD5 571088182ed7e33d986b3aa2c51efd27 2025-10-29
FileHash-MD5 7fa5fb15098efdf76e4c016e2e17bb38 2025-10-29
FileHash-MD5 96b3be4cf3ad232ca456f343f468da0e 2025-10-29