A new malware known as Airstalk has been distributed by a suspected nation-state threat actor as part of a probable supply chain attack.
The cluster is being tracked by Palo Alto Networks Unit 42 under the name CL-STA-1009, where “CL” stands for cluster and “STA” for state-backed incentive.
According to an investigation by security experts Kristopher Russo and Chema Garcia, Airstalk abuses the AirWatch API for mobile device management (MDM), which is now known as Workspace ONE Unified Endpoint Management. It creates a secret command-and-control (C2) channel via the API, mostly to handle file uploads and custom device attributes using the AirWatch feature.
Using a multi-threaded command-and-control (C2) communication protocol, the virus may take screenshots and harvest cookies, browsing history, bookmarks, and screenshots from web browsers read more about Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
