logo

FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

ID: 74b6444d-a95d-5491-ad27-cad0da12b20e

STIX ID: report--74b6444d-a95d-5491-ad27-cad0da12b20e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 describes Operation FlutterBridge, a malvertising campaign targeting macOS users in multiple countries that delivers FlutterShell — a notarized, Flutter-based payload combining adware, backdoor, and data-theft capabilities. The attackers (CL-CRI-1089) use Google/YouTube ads served via shell companies to lure victims into trojanized desktop apps; FlutterShell leverages a WebView JavaScript-to-native bridge to host and change malicious logic remotely, with multiple active variants (PodcastsLounge, PDF-Brain, PDF-Ninja) observed as recently as March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.