Suspected state-backed threat operation CL-STA-1009 has spread the new Airstalk malware in what is believed to be a supply chain attack campaign against the business process outsourcing sector, The Hacker News reports.Intrusions involving Airstalk which exploits AirWatch API for mobile device management, or Workspace ONE Unified Endpoint Management, and comes in PowerShell and .NET versions waits for a "CONNECTED" message after transmitting a "CONNECT" message before executing several actions, including screenshot capturing, Google Chrome cookie exfiltration, Chrome history collection, user directory file enumeration, and self-uninstallation, according to an analysis from Palo Alto Networks Unit 42 researchers.Airstalk's more advanced .NET variant was also found to target Microsoft Edge and the enterprise browser Island, indicating potential targeting of the BPO industry."The evasion techniques employed by this malware allow it to remain undetected in most environments. This is particularly true if the malware is running within a third-party vendor's environment. This is particularly disastrous for organizations that use BPO because stolen browser session cookies could allow access to a large number of their clients," said researchers.
Malware, Supply chain
Novel Airstalk malware deployed in suspected state-backed supply chain intrusion
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
