Pondering my ORB - A look at PolarEdge Adjacent Infrastructure

PolarEdge, Research, Threat Intelligence

UPDATE 9/24/2025: Clarifications on Our PolarEdge Research

We were recently informed by a community member that the certificate highlighted in earlier versions of this research is also present in older versions of Mbed TLS, version 3.4.0, previously known as PolarSSL. Additionally, the TLS certificate we had associated with the “PolarEdge” malware also originates from the same Mbed TLS repository. This new context reduces the confidence of the evidence linking the exposure footprint or the RPX server we analyzed directly to PolarEdge.

While our follow-up investigation  was derived from examining the historical data of a host known to have distributed the PolarEdge payload, it is now believed the actor is leveraging known, exposed certificates as a means of reducing unique attributes. Based on this, we believe the RPX server discussed in the blog was most likely either running on the attacker’s infrastructure or functioning as a relay server.

To ensure our reporting reflects this correction:

Transparency, reproducibility and accuracy are central to our research, and we will continue to clearly acknowledge situations like this in order to provide our community with the most reliable information possible.

AUTHOR
The Censys ARC Research Team

Censys ARC is a team of elite security and threat researchers dedicated to identifying, analyzing, and shedding light on Internet phenomena that impact our world. Using Censys’ Map of the Internet — the world’s most comprehensive, accurate, and up-to-date source for Internet infrastructure — ARC investigates and measures the entirety of the public Internet to share critical and emerging threat intelligence and insights with organizations around the world.