Airstalk Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 3, 2025
Last Seen
November 6, 2025

Airstalk is a malware family that exploits VMware AirWatch MDM (Mobile Device Management) APIs to establish covert command-and-control (C2) communications.

Overview

Airstalk is a malware family that exploits VMware AirWatch MDM (Mobile Device Management) APIs to establish covert command-and-control (C2) communications. By abusing legitimate MDM traffic and tools, it turns enterprise mobility management into hidden spy channels, enabling stealth monitoring and potential control of managed devices. This technique highlights a notable risk where legitimate IT infrastructure can be repurposed for covert operations within enterprises.

Related Threat Clusters

  • Airstalk Malware Exploits MDM Tools in Supply Chain Attacks

    A new malware variant named Airstalk has been discovered, linked to suspected nation-state hackers. This malware targets mobile device management tools, specifically leveraging the AirWatch API to create covert…

    1 article · Updated November 3, 2025
  • Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication

    Airstalk malware has been identified exploiting the AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. This malware leverages vulnerabilities in VMware's…

    3 articles · Updated November 6, 2025
  • Airstalk Malware Exploits MDM Tools in Supply Chain Attacks

    Palo Alto Networks’ Unit 42 has identified a new malware campaign named Airstalk, linked to a suspected nation-state actor. This malware targets mobile device management tools, specifically leveraging the AirWatch API…

    2 articles · Updated November 3, 2025
  • Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication

    Airstalk malware has been identified exploiting vulnerabilities in VMware's AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. Organizations utilizing this MDM…

    4 articles · Updated November 6, 2025

Recent Intelligence Reports

  • Airstalk Malware Leverages AirWatch API MDM Platform to Establish Covert C2 Communication — Cybersecuritynews · November 6, 2025
  • Airstalk Malware Exploits VMware AirWatch MDM APIs for Covert C2 Operations — Cyberpress · November 6, 2025
  • Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication — Gbhackers · November 6, 2025
  • Airstalk Malware Turns MDM Tools into Covert Spy Channels — Esecurityplanet · November 3, 2025
  • Warning issued of new nation state malware targeting browsers — Computing · November 3, 2025

CVSS v3.1 Breakdown