Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication
First seen 2 Dec 2025, 18:33 UTC
•

•92% similarity
•24
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Airstalk malware has been identified exploiting vulnerabilities in VMware's AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. Organizations utilizing this MDM solution are potentially affected, as the malware allows attackers to maintain persistent access to compromised devices.
ThreatCluster AI
How this analysis works