HomeSecurityState hackers develop new Airstalk malware

State-sponsored hackers develop new Airstalk malware

A suspected state-sponsored threat actor has been linked to the distribution of a new malware called Airstalk malware, as part of a possible supply chain attack.

See also: GhostGrab: New Android malware steals banking credentials

Airstalk malware

Palo Alto Networks Unit 42 is tracking the cluster under the name CL-STA-1009, where “CL” stands for cluster and “STA” refers to state support.

“Airstalk abuses the AirWatch API for mobile device management (MDM), now called Workspace ONE Unified Endpoint Management,” security researchers Kristopher Russo and Chema Garcia in an analysis. “It uses the API to establish a covert command and control (C2) channel, primarily through AirWatch’s ability to manage custom device attributes and file uploads.”

The malware appears in PowerShell and .NET variants, using a multi-threaded command-and-control communication protocol. It is capable of capturing screenshots and collecting cookies, browsing history, bookmarks, and screenshots from browsers. The malicious actors are believed to be using a stolen certificate to sign some of the artifacts.

Unit 42 noted that the .NET variant of Airstalk has more capabilities than its PowerShell counterpart, suggesting that it could be an advanced version of the malware.

The PowerShell variant uses the “ /api/mdm/devices/ ” endpoint for C2 communications. While the endpoint is designed to retrieve content details of a specific device, the malware uses the custom attributes feature in the API as a way to store information necessary to interact with the attacker.

Once launched, the backdoor initiates contact by sending a “CONNECT” message and expects a “CONNECTED” message from the server. It then receives various tasks to be performed on the compromised host in the form of “ACTIONS” messages. The result of the execution is sent back to the threat actor using a “RESULT” message.

See also: Herodotus: New Android malware mimics human behavior

State-sponsored hackers develop new Airstalk malware

The backdoor supports seven different ACTIONS, including taking a screenshot, retrieving cookies from Google Chrome, logging all Chrome user profiles, obtaining browsing bookmarks of a specific profile, collecting the browsing history of a specific Chrome profile, listing all files in the user's directory, and uninstalling from the host computer.

The .NET variant of Airstalk extends the capabilities by also targeting Microsoft Edge and Island, an enterprise-focused browser, while attempting to emulate an AirWatch (“AirwatchHelper.exe”). It also supports three more message types:

– MISMATCH, to flag version mismatch errors
– DEBUG, to send debugging messages

Additionally, it uses three different threads of execution, each serving a unique purpose: for managing C2 tasks, exporting the debug log, and communicating with the C2 server. The malware also supports a broader set of commands, although one of them appears to have not yet been implemented:

– Screenshot, to take a screenshot
– UpdateChrome, to export a specific Chrome profile
– FileMap, to list the contents of a specific directory
– RunUtility (not implemented)
– EnterpriseChromeProfiles, to retrieve available Chrome profiles
– UploadFile, to export specific Chrome artifacts and credentials
– OpenURL, to open a new URL in Chrome
– Uninstall, to complete the process
– EnterpriseChromeBookmarks, to retrieve Chrome bookmarks from a specific user profile
– EnterpriseIslandProfiles, to retrieve available Island browser profiles
– UpdateIsland, to export a specific Island browser profile
– ExfilAlreadyOpenChrome, to discard all cookies from the current Chrome profile

See also: Salt Typhoon breached a European Telecom Network with Snappybee malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

State-sponsored hackers develop new Airstalk malware

Interestingly, while the PowerShell variant uses a scheduled task for persistence, the .NET version does not have such a mechanism.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS