Story perspectives
Airstalk Malware Exposes Data Risks for BPO Firms
11/1/2025
44 9
1 of 1
Story summary
- Airstalk, a newly identified malware, is linked to a suspected nation-state actor.
- Palo Alto Networks Unit 42 researchers report that Airstalk exploits the AirWatch API, now VMware Workspace ONE UEM, to establish covert command-and-control channels.
- The malware exists in PowerShell and .NET variants and can harvest data from Chrome and Microsoft Edge.
- Analysts warn that targeting BPO companies could fuel widespread data breaches via stolen session cookies.
