Airstalk is a Windows malware family reported by Palo Alto Networks Unit 42 and associated with threat activity cluster CL-STA-1009. Unit 42 assessed with medium confidence that it was used by a possible nation-state actor in a likely supply chain attack, with multiple references indicating suspected Chinese state-sponsored involvement. The malware has been observed in two variants, one written in PowerShell and one in .NET, with the .NET variant described as more mature and feature-rich.
Airstalk’s defining characteristic is abuse of VMware AirWatch, now Workspace ONE Unified Endpoint Management (UEM), mobile device management APIs as a covert command-and-control channel. It uses the AirWatch custom device attributes feature as a dead-drop style C2 mechanism and also uses the blob upload endpoint /api/mam/blobs/uploadblob for exfiltration. The PowerShell variant uses the /api/mdm/devices/ endpoint and a JSON-based protocol with message types including CONNECT, CONNECTED, ACTIONS, and RESULT. The .NET variant extends the protocol with MISMATCH, DEBUG, and PING, uses three threads for task handling, debug-log exfiltration, and beaconing, and periodically uploads debug logs every 10 minutes.
The malware is designed primarily for espionage and data theft. Reported capabilities include taking screenshots; enumerating user files; listing browser profiles; and stealing browser cookies, browsing history, and bookmarks. The PowerShell variant targets Chrome and can steal cookies by enabling Chrome remote debugging and restarting Chrome with profile-specific parameters. The .NET variant expands targeting to Google Chrome, Microsoft Edge, and Island Browser, and supports commands such as Screenshot, FileMap, UploadFile, OpenURL, EnterpriseChromeBookmarks, EnterpriseIslandProfiles, UpdateChrome, UpdateIsland, ExfilAlreadyOpenChrome, and Uninstall. Some reporting also notes partially implemented task scaffolding such as RunUtility.
Persistence and operational behavior differ by variant. The PowerShell variant uses a scheduled task for persistence and removes it during uninstall. The .NET variant reportedly lacks the same persistence mechanism and instead signals completion or uninstall through the custom attributes channel. Some reporting states it attempts to mimic an AirWatch helper utility named AirwatchHelper.exe.
The campaign context indicates elevated risk to business process outsourcing (BPO) providers and other third-party vendor environments, where broad access to client systems can make browser session theft and monitoring especially valuable for downstream compromise. Unit 42 noted that distribution and victimology were not fully known at the time of reporting, but the use of Workspace ONE/AirWatch APIs and enterprise browser targeting was highlighted as consistent with supply chain intrusion scenarios.
Airstalk also employed evasion and trust-abuse techniques. Some .NET samples were signed with a likely stolen certificate issued to Aoteng Industrial Automation (Langfang) Co., Ltd., which was reportedly revoked shortly after issuance. Later samples reportedly showed PE timestamp manipulation. Reported sample hashes include dfdc27d81a6a21384d6dba7dcdc4c7f9348cf1bdc6df7521b886108b71b41533, b6d37334034cd699a53df3e0bcac5bbdf32d52b4fa4944e44488bd2024ad719b, 4e4cbaed015dfbda3c368ca4442cd77a0a2d5e65999cd6886798495f2c29fcd5, and PowerShell sample 3a48ea6857f1b6ae28bd1f4a07990a080d854269b1c1563c9b2e330686eb23b5. Two signed testing PE binaries were also listed with SHA256 hashes 0c444624af1c9cce6532a6f88786840ebce6ed3df9ed570ac75e07e30b0c0bde and 1f8f494cc75344841e77d843ef53f8c5f1beaa2f464bcbe6f0aacf2a0757c8b5.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"A suspected nation-state threat actor has been linked to the distribution of a new malware called Airstalk as part of a likely supply chain attack."
2 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Airstalk is a sophisticated Windows-based malware family with two main variants: a PowerShell loader and a .NET backdoor. It abuses VMware Workspace ONE (AirWatch) MDM APIs to establish covert command-and-control channels and exfiltrate sensitive data. The malware is designed for stealth, blending its traffic with legitimate MDM operations, and is primarily used for espionage against BPO providers and their clients.
Airstalk is a Windows malware strain targeting Omnissa Workspace ONE environments, used to exfiltrate browser data and take screenshots, likely by a nation-state actor. It has both Powershell and .NET variants, with the .NET version being more sophisticated.
Airstalk is a new malware used in a supply chain attack by a suspected nation-state threat actor.
Windows malware family (PowerShell and .NET variants) that abuses VMware AirWatch/Workspace ONE UEM APIs to create covert C2 via custom device attributes and file upload features; assessed as used in a likely supply-chain attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.