CL-STA-1009 is a suspected state-backed threat activity cluster assessed with medium confidence to be linked to Chinese espionage operations. The cluster is associated with Airstalk, a Windows malware family observed in PowerShell and .NET variants and used in likely supply chain intrusions. Activity attributed to this cluster has focused on compromising business process outsourcing (BPO) organizations, which can provide indirect access to clients’ critical business systems and downstream enterprise environments. Airstalk is notable for abusing VMware AirWatch, now Workspace ONE Unified Endpoint Management, as a covert command-and-control channel by misusing mobile device management APIs, including custom device attributes and file-upload functionality. The malware uses a multi-threaded communications design and dead-drop-style tasking to reduce direct operator exposure. Observed capabilities include screenshot capture, browser data theft, file enumeration, and exfiltration of browser artifacts such as cookies, bookmarks, and browsing history. The more capable .NET variant expands targeting beyond Chrome to Microsoft Edge and Island Browser and includes additional tasking and beaconing functionality. The cluster demonstrates strong defense-evasion tradecraft. Reported measures include signing malware with likely stolen certificates, use of a revoked certificate, timestamp manipulation to complicate forensic correlation, and in some cases self-removal behavior after exfiltration. The PowerShell variant has used scheduled-task persistence, while the .NET variant appears designed for stealthier post-compromise operation. Overall behavior is consistent with long-term clandestine access, data collection, and downstream compromise through trusted third-party relationships rather than disruptive or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unattributed activity cluster associated with a likely supply-chain intrusion using the Airstalk malware family, which abuses the AirWatch/Workspace ONE UEM API to create a covert C2 channel via device attributes and file upload features.
Named activity cluster tracked by Unit 42 associated with the Airstalk Windows malware family. The activity is assessed (medium confidence) as likely nation-state espionage leveraging a supply-chain compromise and abusing VMware AirWatch/Workspace ONE MDM APIs as a covert C2 'dead drop' channel to steal browser data, credentials, screenshots, and exfiltrate files while blending into legitimate MDM traffic.
A suspected state-backed activity cluster linked to distribution of the Airstalk malware, likely via a supply-chain compromise. The malware abuses VMware AirWatch/Workspace ONE MDM APIs as a covert C2 channel and focuses on browser data theft (cookies, history, bookmarks) and screenshots, with indications of signed artifacts using a likely stolen certificate.
Suspected Chinese state-sponsored activity cluster conducting supply-chain intrusions via business process outsourcing (BPO) providers, deploying the Airstalk malware family that abuses the AirWatch MDM API for covert C2 and browser data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.