logo

Hackers Deploy FlutterShell Backdoor Through Malvertising Campaigns

ID: 09a9bd87-cedd-50f7-b9de-be3464e2ca46

STIX ID: report--09a9bd87-cedd-50f7-b9de-be3464e2ca46

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Varshini

...
...

Researchers tracked a financially motivated campaign (Operation FlutterBridge) in which the CL-CRI-1089 cluster distributes a notarized macOS backdoor named FlutterShell via malicious desktop apps promoted through large Google Ads purchases; the malware uses a Flutter WebView and a JavaScript-to-native bridge to fetch remote malicious scripts, avoid static detection, and perform actions including Chrome search-provider hijacking, with multiple SHA256 indicators provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.