Palo Alto Networks' Unit 42 identified a new Windows-based malware family named Airstalk, which leverages the VMware AirWatch (Workspace ONE) mobile device management (MDM) API to establish a covert command-and-control (C2) channel. The malware, attributed to a likely nation-state threat actor and tracked as activity cluster CL-STA-1009, was deployed in a suspected supply chain attack targeting organizations through trusted third-party vendors and business process outsourcing (BPO) providers. Airstalk is available in both PowerShell and .NET variants, with the .NET version exhibiting more advanced capabilities, including multi-threaded C2 communication and versioning, and in some cases, the use of a likely stolen certificate for signing.
Airstalk is designed to exfiltrate sensitive browser data such as cookies, browsing history, bookmarks, and screenshots, while evading detection by abusing legitimate cloud service APIs. The campaign highlights the risk posed by supply chain compromises, as infiltrating a single vendor can provide access to numerous downstream targets. The malware's use of the AirWatch MDM API for C2 communications demonstrates a sophisticated approach to blending malicious activity with legitimate enterprise traffic, complicating detection and response efforts for affected organizations.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 publicly reported a new Windows malware family called Airstalk and assessed with medium confidence that a possible nation-state actor used it in a likely supply-chain attack tracked as CL-STA-1009. The report described PowerShell and .NET variants that abuse VMware AirWatch/Workspace ONE UEM APIs for covert command-and-control and data exfiltration.
Researchers found some Airstalk .NET samples were signed with a likely stolen certificate issued to Aoteng Industrial Automation (Langfang) Co., Ltd. The certificate was reportedly revoked shortly after issuance, suggesting an attempt to make the malware appear legitimate.
Unit 42 reported that early Airstalk .NET builds showed a compilation timestamp of June 28, 2024, helping reconstruct the malware's development timeline. Later samples also showed timestamp manipulation, indicating efforts to obscure development history.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcescworld.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.