Operation FlutterBridge Malware Targets macOS Platforms with Backdoor Capabilities
ID: 345433fe-6321-56bf-a463-0634a563556c
STIX ID: report--345433fe-6321-56bf-a463-0634a563556c
Feed Name: securityonline.info
Operation FlutterBridge is a widespread malvertising-driven campaign targeting Apple desktop users: attackers purchase legitimate ad placements, lure victims to rogue installers for signed macOS apps (masquerading as productivity tools), and use a WebView-based JavaScript-to-native bridge to load remote scripts that enable backdoor capabilities. The implant performs browser hijacking, arbitrary command execution, local filesystem access, and exfiltrates files by proxying them through an attacker-controlled AI summarization endpoint; analysts link the infrastructure to other Windows strains under a single criminal cluster.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
