Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
A new malware known as Airstalk has been distributed by a suspected nation-state threat actor as part of a probable supply chain attack.
The cluster is being tracked by Palo Alto Networks Unit 42 under the name CL-STA-1009, where "CL" stands for cluster and "STA" for state-backed incentive.
According to an investigation by security experts Kristopher Russo and Chema Garcia, Airstalk abuses the AirWatch API for mobile device management (MDM), which is now known as Workspace ONE Unified Endpoint Management. It creates a secret command-and-control (C2) channel via the API, mostly to handle file uploads and custom device attributes using the AirWatch feature.
Using a multi-threaded command-and-control (C2) communication protocol, the virus may take screenshots and harvest cookies, br...





