logo

Hackers Use Malicious Ads to Deliver FlutterShell Backdoor on macOS Systems

ID: 66882230-ea07-59c0-94e4-8374350099f0

STIX ID: report--66882230-ea07-59c0-94e4-8374350099f0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Tushar Subhra Dutta

...
...

Unit 42 tracked Operation FlutterBridge, a global malvertising campaign using hundreds of verified Google Ads accounts to push notarized macOS applications (PodcastsLounge, PDF-Brain, PDF-Ninja) that install a backdoor named FlutterShell. The backdoor leverages a WebView to fetch remote attack logic (flutterInvoke), gives attackers full remote control, silently modifies Chrome settings and exfiltrates data (including via an AI summarization feature), and includes multiple active C2 domains and SHA256 IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.