SYMBOLCOMMON_NAMEaka. SYNONYMS
win.airstalk (Back to overview)

Airstalk

Actor(s): CL-STA-1009


According to Unit 42, this malware steals information from browsers and uses a covert channel through the AirWatch API.

References
2025-10-29Palo Alto Networks Unit 42Chema Garcia, Kristopher Russo
Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack
Airstalk CL-STA-1009

There is no Yara-Signature yet.