Airstalk is a malware family that exploits VMware AirWatch MDM (Mobile Device Management) APIs to establish covert command-and-control (C2) communications.
Airstalk is a malware family that exploits VMware AirWatch MDM (Mobile Device Management) APIs to establish covert command-and-control (C2) communications. By abusing legitimate MDM traffic and tools, it turns enterprise mobility management into hidden spy channels, enabling stealth monitoring and potential control of managed devices. This technique highlights a notable risk where legitimate IT infrastructure can be repurposed for covert operations within enterprises.
A new malware variant named Airstalk has been discovered, linked to suspected nation-state hackers. This malware targets mobile device management tools, specifically leveraging the AirWatch API to create covert…
Airstalk malware has been identified exploiting the AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. This malware leverages vulnerabilities in VMware's…
Palo Alto Networks’ Unit 42 has identified a new malware campaign named Airstalk, linked to a suspected nation-state actor. This malware targets mobile device management tools, specifically leveraging the AirWatch API…
Airstalk malware has been identified exploiting vulnerabilities in VMware's AirWatch Mobile Device Management (MDM) platform to establish covert command and control (C2) communication. Organizations utilizing this MDM…