logo

Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor

ID: cbfb09c7-ca2e-5c2b-88ec-a1bc0a3b07f5

STIX ID: report--cbfb09c7-ca2e-5c2b-88ec-a1bc0a3b07f5

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

Author: Deeba Ahmed

...
...

Palo Alto Networks Unit 42 reports on Operation FlutterBridge, a malvertising campaign that used fake, verified Google/YouTube ads and shell companies to push macOS apps (PodcastsLounge, PDF-Brain, PDF-Ninja) bundling a backdoor called FlutterShell; the malware loads remote JavaScript, hijacks Chrome via Secure Preferences to force ad-filled pages, can execute arbitrary commands, access files and exfiltrate environment data, and is under active development with multiple evolving variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.