Malware

PolarEdge botnet’s inner workings examined

botnet bot-net computer virus

Operations of the PolarEdge botnet which was previously noted to have targeted Asus, QNAP, and Synology routers, as well as resemble an Operational Relay Box network were discovered to either involve functioning as a TLS client for remote file downloads or on-the-fly configuration modifications, The Hacker News reports.

Execution of PolarEdge prompts default TLS server functioning to facilitate host fingerprint delivery to the command-and-control server and the erasure of some files for a still undetermined purpose, according to Sekoia researchers. Multiple anti-analysis approaches are then harnessed by PolarEdge to circumvent detection.

"Although the backdoor does not ensure persistence across reboots, it calls fork to spawn a child process that, every 30 seconds, checks whether /proc/<parent-pid> still exists. If the directory has disappeared, the child executes a shell command to relaunch the backdoor," said researchers.

Such findings follow a Synthient report detailing the transformation of breached devices into SOCKS5 residential proxies using the GhostSocks malware-as-a-service tool.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds