Threats Tagged 'airstalk'
View all threats tagged with 'airstalk'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'airstalk'
Click on any threat for detailed analysis and mitigation recommendations
Airstalk is a newly discovered Windows-based malware family used by a suspected nation-state actor, CL-STA-1009, in supply chain attacks targeting business process outsourcing companies. It exists in PowerShell and . NET variants, with the latter exhibiting advanced features such as multi-threaded command-and-control (C2) protocols, versioning, and signed binaries. The malware abuses the AirWatch API for mobile device management to covertly communicate with its C2 infrastructure. It exfiltrates sensitive browser data including cookies, history, and bookmarks, enabling extensive data theft. Its evasion techniques and adaptive behavior make it particularly dangerous in third-party vendor environments. No known public exploits exist yet, but the threat poses a medium severity risk with potential for significant impact on confidentiality and operational security. European organizations relying on outsourcing and mobile device management solutions are at elevated risk, especially in countries with strong BPO sectors. Mitigation requires enhanced supply chain security, monitoring of AirWatch API usage, and behavioral detection of anomalous PowerShell and . NET activities. Join the discussion | AlienVault OTX General | 10/29/2025, 12:35:47 UTC Added: 10/29/2025, 13:30:11 UTC |
Showing 1 to 1 of 1 result