Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack
ID: 1ab8c33a-b316-5389-91f3-e5b3029a9765
STIX ID: report--1ab8c33a-b316-5389-91f3-e5b3029a9765
Feed Name: Palo Alto Networks Unit 42
Unit42 identifies and analyzes Airstalk, a Windows information-stealing malware available in PowerShell and .NET variants that uses the AirWatch/Workspace ONE MDM API as a covert C2 channel to exfiltrate browser cookies, history, bookmarks, and screenshots; the .NET variant is more advanced (multi-threaded C2, versioning, beaconing) and some binaries were signed with a likely stolen certificate. The report assesses with medium confidence that a nation-state actor deployed Airstalk in a supply-chain compromise, provides IoCs (SHA256s and certificate), describes tactics and persistence, and recommends detection/protection measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
