polaris botnet

Bot User-Agent: polaris-botnet

⚠️ Overview

Polaris botnet is a distributed denial-of-service (DDoS) botnet first publicly documented in August 2021 by Lumen Technologies' Black Lotus Labs research team. It is maintained by unknown threat actors who primarily compromise Internet-facing MicroTik RouterOS devices by exploiting the directory traversal vulnerability tracked as CVE-2018-14847 to gain initial access and deploy a modular payload. The botnet's name references the Polaris star, reflecting the operators' use of celestial-themed naming conventions in their infrastructure.

🔧 Technical Capabilities

Polaris leverages a multi-stage infection chain: an initial scanner module probes for vulnerable MicroTik devices on port 8291 (Winbox), then uses the CVE-2018-14847 exploit to read the device's user database and obtain administrative credentials. Once inside, it downloads a shell script that establishes persistence by modifying the router's startup configuration and installs a main bot binary capable of executing a variety of DDoS attack vectors, including UDP floods, TCP SYN floods, HTTP GET/POST floods, and DNS amplification attacks. The botnet employs a hierarchical command-and-control (C2) architecture with multiple layers of proxies to obscure the central servers, and it uses encrypted communication over custom protocols to evade detection. Polaris also has a self-update mechanism that pulls new modules from a remote repository, allowing it to add capabilities or change C2 endpoints dynamically.

📜 History & Notable Incidents

The Black Lotus Labs report from August 2021 revealed that Polaris had been active since at least June 2021 and had compromised over 1,500 MicroTik devices across multiple countries. The botnet was observed launching a sustained attack against a major U.S. content distribution network, generating traffic peaks exceeding 100 Gbps. In October 2022, a separate analysis by QiAnXin Threat Intelligence linked Polaris to a broader campaign targeting routers in South America and Asia, noting that the botnet's operators had updated their exploit code to also target D-Link and TP-Link devices using known vulnerabilities like CVE-2021-27256. As of early 2024, Polaris remains active, with periodic infrastructure reshuffles to avoid sinkholing.

🔍 Detection Indicators

Polaris scanning traffic exhibits a distinctive pattern: repeated connection attempts to port 8291 from a single IP address using a User-Agent of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36". Compromised devices show irregular outbound connections to non-standard ports (e.g., TCP 4433, 8443) for C2 communication, and an increase in DNS queries for domains with "polar" or "star" substrings. Network flow logs often reveal large volumes of UDP traffic from the same device to random destination ports, indicating an active flood attack.

☠️ Risk & Impact

Polaris can saturate network links with multi-vector DDoS attacks, causing service outages for online platforms, e-commerce sites, and critical infrastructure. The botnet's persistence mechanisms on compromised routers allow attackers to maintain control even after device reboots, and the modular architecture means operators can pivot to data exfiltration or lateral movement within internal networks. Organizations with unpatched MicroTik devices risk having their internet gateways weaponized for large-scale attacks, potentially leading to legal liability and reputational damage.

🛡️ Mitigation

Because Polaris botnet poses an immediate threat to network availability and can be repurposed for other malicious activities, any detected traffic matching its indicators — especially scans on port 8291 or C2 connections to known malicious IPs — is blocked immediately on detection without further analysis. The primary defense is patching the underlying vulnerabilities (e.g., CVE-2018-14847) and restricting remote administration access to trusted IP ranges. Network administrators should also deploy behavioral monitoring to flag unusual outbound traffic patterns from router infrastructure.

🛡️

Stop Bots. Save Bandwidth. Protect Revenue.

Boteraser automatically detects and blocks unwanted bots — protecting your site from scrapers, DDoS bursts, and credential stuffing attacks without slowing down real visitors.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.