ThreatCluster

Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication

First seen 6 Nov 2025, 17:37 UTC GbhackersCyberpressCybersecuritynews 91% similarity 48

Article Content

Browse articles
ThreatCluster

Airstalk malware has been identified exploiting the AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. This malware leverages vulnerabilities in VMware's AirWatch APIs, potentially affecting organizations utilizing this MDM solution. The exploitation allows attackers to maintain persistent access to compromised devices.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story