Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
thehackernews.com·1d
Flag this post

Oct 31, 2025Ravie LakshmananMalware / Browser Security

A suspected nation-state threat actor has been linked to the distribution of a new malware called Airstalk as part of a likely supply chain attack.

Palo Alto Networks Unit 42 said it’s tracking the cluster under the moniker CL-STA-1009, where “CL” stands for cluster and “STA” refers to state-backed motivation.

“Airstalk misuses the AirWatch API for mobile device management (MDM), which is now called Workspace ONE Unified Endpoint Management,” security researchers Kristopher Russo and Chema Garcia said in an analysis. “It uses the API to establish a covert command-and-control (C2) channel, primarily through the AirWatch feature to manag…

Similar Posts

Loading similar posts...