logo

Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack

ID: 1ab8c33a-b316-5389-91f3-e5b3029a9765

STIX ID: report--1ab8c33a-b316-5389-91f3-e5b3029a9765

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-10-29

Date Updated: 2026-04-28

Author: Kristopher Russo and Chema Garcia

...
...

Unit42 identifies and analyzes Airstalk, a Windows information-stealing malware available in PowerShell and .NET variants that uses the AirWatch/Workspace ONE MDM API as a covert C2 channel to exfiltrate browser cookies, history, bookmarks, and screenshots; the .NET variant is more advanced (multi-threaded C2, versioning, beaconing) and some binaries were signed with a likely stolen certificate. The report assesses with medium confidence that a nation-state actor deployed Airstalk in a supply-chain compromise, provides IoCs (SHA256s and certificate), describes tactics and persistence, and recommends detection/protection measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.