Skip to content
Warning issued of new nation state malware targeting browsers

Warning issued of new nation state malware targeting browsers

Computing • November 3, 2025

A suspected nation state attacker is deploying a new Windows malware variant called Airstalk as part of a possible supply chain attack.

Airstalk leverages the AirWatch API for mobile device management (now called Workspace ONE Unified Endpoint Management), according to Palo Alto Networks’ Kristopher Russo and Chema Garcia.

“[Airstalk] uses the API to establish a covert command-and-control (C2) channel, primarily through the AirWatch feature to manage custom device attributes and file uploads,” they said.

The researchers, part of Palo Alto’s Unit 42 group, are tracking the malware as CL-STA-1009.

Airstalk is able to harvest cookies, browsing history, bookmarks and screenshots from web browsers.

The malware appears in both PowerShell and .NET variants, with the latter featuring more capabilities. The researchers say it appears to be in “a more advanced stage of development.”

While the PowerShell version only targets Google Chrome, the .NET variant is also capable of attacking Microsoft Edge and the enterprise-focused Island Browser.

Although the researchers have warned the malware, they do not yet know how it is distributed or any potential victims. However, several factors – including the use of MDM-related APIs and the targeting of an enterprise browser like Island – suggest a supply chain attack, specifically one aimed at the business process outsourcing (BPO) sector.

“We’ve seen a notable increase of attacks on BPOs as the source of intrusion in incidents we've seen over the past few years,” Russo and Garcia write.

“BPOs typically leverage the economy of scale to have highly specialised talent service multiple clients concurrently. While this can generate significant savings for both the BPO and its clients, it has the drawback of allowing the BPO to act as a gateway into multiple targets. Attackers are willing to invest generously in the resources necessary to not only compromise them but maintain access indefinitely.”

Airstalk’s evasion techniques mean it is able to remain undetected in most environments, especially in those belonging to a third party. As always with low and slow attacks the best method of detection is behavioural analysis, rather than a pure technical solution.