Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication
First seen 6 Nov 2025, 17:37 UTC
•

•91% similarity
•48
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Airstalk malware has been identified exploiting the AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. This malware leverages vulnerabilities in VMware's AirWatch APIs, potentially affecting organizations utilizing this MDM solution. The exploitation allows attackers to maintain persistent access to compromised devices.
ThreatCluster AI
How this analysis works