Operation FlutterBridge: The FlutterShell macOS Backdoor
ID: b2e99f0a-b243-53e4-b490-dc7a4b73b68c
STIX ID: report--b2e99f0a-b243-53e4-b490-dc7a4b73b68c
Feed Name: LevelBlue SpiderLabs Blog
This report analyzes ten macOS Mach-O artifacts from the CL-CRI-1089 cluster (Operation FlutterBridge), describing FlutterShell — a Flutter-based malware that uses a WKWebView to fetch JavaScript C2 payloads at runtime. Key findings include an invariant exported-symbol fingerprint across generations, heavy Dart AOT obfuscation in Gen 3, certificate rotation and notarization abuse to evade Gatekeeper, C2-conditional dormancy in sandboxes, concrete IOCs (domains, hashes, plugin-typo string), and recommended tiered detection rules for endpoint telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
