logo

Operation FlutterBridge Malware Targets macOS Platforms with Backdoor Capabilities

ID: 345433fe-6321-56bf-a463-0634a563556c

STIX ID: report--345433fe-6321-56bf-a463-0634a563556c

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

Operation FlutterBridge is a widespread malvertising-driven campaign targeting Apple desktop users: attackers purchase legitimate ad placements, lure victims to rogue installers for signed macOS apps (masquerading as productivity tools), and use a WebView-based JavaScript-to-native bridge to load remote scripts that enable backdoor capabilities. The implant performs browser hijacking, arbitrary command execution, local filesystem access, and exfiltrates files by proxying them through an attacker-controlled AI summarization endpoint; analysts link the infrastructure to other Windows strains under a single criminal cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.