Security researchers have discovered a new, sophisticated malware family that targets corporate environments through a supply chain breach. The malware, tracked as Airstalk, represents a significant shift in the way attackers exploit legitimate enterprise management tools to evade detection and maintain persistent access to compromised systems.
See also: Sandworm targets Ukraine with data wiper malware

This discovery highlights the growing vulnerability of business process outsourcing organizations and third-party vendors that manage critical infrastructure on behalf of larger enterprises. Airstalk operates in two distinct flavors, PowerShell and .NET, with both versions leveraging the AirWatch API, now known as VMware Workspace ONE Unified Endpoint Management.
The malware’s primary distinction lies in its abuse of legitimate mobile device management infrastructure to establish command and control communications, allowing attackers to remain invisible to traditional security monitoring systems. This technique allows hackers to hide malicious traffic within legitimate management API calls, effectively bypassing the network-based detection mechanisms that organizations typically rely on.
Palo Alto Networks security analysts identified the malware after discovering evidence suggesting that a potential state-sponsored threat actor deployed Airstalk through a carefully orchestrated supply chain attack. The research team created the threat activity cluster CL-STA-1009 to track ongoing activity associated with this malware family.
See also: Google warns of new AI-powered malware families

The malware's sophisticated design and multi-threaded architecture suggest significant investment in development resources, consistent with state-of-the-art threat actors prioritizing long-term persistence over quick operational gains. The discovered samples demonstrate advanced capabilities, including sensitive browser data extraction, screenshot capture, and sophisticated persistence mechanisms.
Both variants target Google Chrome, although the more advanced .NET variant extends its reach to Microsoft Edge and Island Browser. The malware creates a modular framework where threat actors can selectively implement or disable specific features, providing flexibility to businesses and potentially serving as a development platform for future variants.
The most innovative aspect of Airstalk involves implementing a “dead drop” communication channel using the AirWatch MDM API’s custom device attributes feature. Instead of establishing direct connections to the attackers’ infrastructure, the malware exchanges messages in JSON format through the legitimate MDM platform, effectively using enterprise management tools as intermediaries to transmit commands and extract data.
The communication protocol operates through specific API endpoints, with the malware querying the device endpoint (/api/mdm/devices/) to retrieve and store command information. The messages contain required fields, including CLIENT_UUID, which is derived from Windows Management Instrumentation data, and SERIALIZED_MESSAGE, which contains Base64-encoded JSON payloads.
See also: XLoader malware analyzed with the help of ChatGPT

This design allows malware to maintain operational security by avoiding direct network connections to suspicious infrastructure. The C2 protocol uses message types for different operational stages, including CONNECT for initial communication, CONNECTED for confirmation, ACTIONS for task recovery, and RESULT for data extraction.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
