logo

Operation FlutterBridge: The FlutterShell macOS Backdoor

ID: b2e99f0a-b243-53e4-b490-dc7a4b73b68c

STIX ID: report--b2e99f0a-b243-53e4-b490-dc7a4b73b68c

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Maor Gabay

...
...

This report analyzes ten macOS Mach-O artifacts from the CL-CRI-1089 cluster (Operation FlutterBridge), describing FlutterShell — a Flutter-based malware that uses a WKWebView to fetch JavaScript C2 payloads at runtime. Key findings include an invariant exported-symbol fingerprint across generations, heavy Dart AOT obfuscation in Gen 3, certificate rotation and notarization abuse to evade Gatekeeper, C2-conditional dormancy in sandboxes, concrete IOCs (domains, hashes, plugin-typo string), and recommended tiered detection rules for endpoint telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.