Malware, Supply chain

Novel Airstalk malware deployed in suspected state-backed supply chain intrusion

Privacy concept: pixelated words Malware on digital background, 3d render

Suspected state-backed threat operation CL-STA-1009 has spread the new Airstalk malware in what is believed to be a supply chain attack campaign against the business process outsourcing sector, The Hacker News reports.

Intrusions involving Airstalk which exploits AirWatch API for mobile device management, or Workspace ONE Unified Endpoint Management, and comes in PowerShell and .NET versions waits for a "CONNECTED" message after transmitting a "CONNECT" message before executing several actions, including screenshot capturing, Google Chrome cookie exfiltration, Chrome history collection, user directory file enumeration, and self-uninstallation, according to an analysis from Palo Alto Networks Unit 42 researchers.

Airstalk's more advanced .NET variant was also found to target Microsoft Edge and the enterprise browser Island, indicating potential targeting of the BPO industry.

"The evasion techniques employed by this malware allow it to remain undetected in most environments. This is particularly true if the malware is running within a third-party vendor's environment. This is particularly disastrous for organizations that use BPO because stolen browser session cookies could allow access to a large number of their clients," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds