Hackers Deploy FlutterShell Backdoor Through Malvertising Campaigns
ID: 09a9bd87-cedd-50f7-b9de-be3464e2ca46
STIX ID: report--09a9bd87-cedd-50f7-b9de-be3464e2ca46
Feed Name: Cyber Press
Threat Score
Researchers tracked a financially motivated campaign (Operation FlutterBridge) in which the CL-CRI-1089 cluster distributes a notarized macOS backdoor named FlutterShell via malicious desktop apps promoted through large Google Ads purchases; the malware uses a Flutter WebView and a JavaScript-to-native bridge to fetch remote malicious scripts, avoid static detection, and perform actions including Chrome search-provider hijacking, with multiple SHA256 indicators provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
