CL-STA-1009

MISP
Type:
Unknown
Country:
Unknown
First seen:
Unknown
Details:

CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell and .NET variants. The .NET variant features a multi-threaded C2 protocol, versioning, and complex tasks, employing defense evasion techniques such as signed binaries with a revoked certificate and manipulation of PE timestamps. The malware is believed to have been used in supply chain attacks, with a development timeline established through signed timestamps. The persistent threat posed by this actor is underscored by the adaptive nature of the malware.

Metadata
ID: 1014
Created: 10/02/2026 16:00
Updated: 07/03/2026 04:00