INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Operation FlutterBridge Malicious Backdoor Spreads

| 2026-06-02 10:00 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The FlutterShell malware has been linked to a widespread operation known as Operation FlutterBridge, which targets macOS users through an extensive Google Ads campaign. This cluster of activity began in 2023 and continues to this day, with the attackers using malvertising campaigns to spread malicious payloads via separate operations such as RecipeLister and Calibre. The payload delivers FlutterShell, infecting targets with adware that exfiltrates data through artificial intelligence summarization features. As a result, these companies appear to be legitimate Ukraine and UK-based enterprises, registered years before the malicious activity started, but they are actually shell companies tied to Operation FlutterBridge.
Technical Mitigations AI-generated
• Implement a Web Application Firewall (WAF) to detect and block malicious traffic, including the use of IP blocking or rate limiting. • Utilize cloud-based security services such as Google Cloud Security Command Center or AWS Shield to monitor and protect against FlutterShell attacks. • Configure macOS operating system settings to limit the execution of arbitrary JavaScript code through web views.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

021666••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
48047c••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
8421c9••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b60074••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
co•••••.read
co•••••.podcastslounge
or•••••.sparkle
co•••••.app
ch•••••.js
up•••••.html
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign InfrastructureCampaign InfrastructureCampaign Background CLCampaign Background CLCampaign Spreads NewCampaign Spreads NewOperation FlutterBridgeOperation FlutterBridge
Target & Sectors
NORTH_AMERICA NORTH_AMERICA FIVE_EYES FIVE_EYES DACH DACH
Incident Timeline
‎late 2025
Threat actors used fake Google Ads to target PodcastsLounge, a macOS app.
campaign Operation FlutterBridge
infrastructure Macos
organisation PodcastsLounge
general_metric 1 Version
‎early 2025
Threat actors used fake Google Ads to target macOS users.
campaign Campaign Infrastructure
organisation Cortex XDR
organisation CL-CRI-1089: Campaign Infrastructure
organisation CL-CRI-1089’s
‎August 2025
Threat actors used Apple systems to target users with the JSCoreRunner campaign, which included a fake Google Ads targeting strategy.
organisation FileRipple
organisation Apple
‎late August 2025
Threat actors used fake Google Ads to target macOS devices in the late August 2025 incident.
organisation Palo Alto Networks Unit
‎January 19, 2026
Threat actors used Fake Google Ads to target macOS devices on January 19, 2026.
‎February 2026
Researchers discovered that PodcastsLounge used fake Google ads to spread the macOS backdoor FlutterShell.
organisation PodcastsLounge
general_metric 1 Version
‎early February 2026
Threat actors used fake Google Ads to target Windows operating systems.
infrastructure Windows
‎March 2026
Threat actors used fake Google Ads to target macOS devices.
‎2026/06/02
The attackers used fake Google Ads to spread the macOS backdoor called FlutterShell, which was initially launched through a legitimate podcast player application named PodcastsLounge.
organisation LTD
organisation Mac
infrastructure Macos
organisation Target
organisation Operation FlutterBridge
organisation FlutterShell
organisation Anglophone
organisation Spread macOS Backdoor.
organisation Google
infrastructure Windows
organisation Operations
organisation Calendaromatic Windows
organisation The CL-CRI-1089 Connection
infrastructure Linux
organisation FlutterShell’s Update Mechanism
organisation FlutterShell Backdoor Spreads
organisation Malicious Google
organisation PDF
organisation TamperedChef
organisation CL-CRI-1089
organisation The JSCoreRunner Connection In
organisation FileRipple
organisation UI Manipulation
organisation XSIAM
organisation Palo Alto Networks
organisation WebView
organisation HTML
organisation Apple Developer
organisation Apple
organisation Timeline
organisation File
organisation FW9NHQ8922
organisation Sparkle
organisation HOME/Library/Caches
organisation YouTube
organisation Google Chrome
organisation FlutterShell Deployment and
organisation VirusTotal
organisation PodcastsLounge
organisation PDF-Brain
organisation PDF-
organisation FlutterShell Technical Analysis
organisation /getUpdateThanksConfig
organisation Descriptive
organisation /bin/sh
organisation Binary Obfuscation None None Flutter
organisation etoftheappyrince[.]org healightejustb[.]org
organisation FlutterShell’s Adware Payload
organisation sinterfumesco[.]com
organisation Secure Preferences
organisation CL-CRI-1089 Ads Delivery Network
organisation Verified Shell Entities
organisation the Google Ads Transparency Center
organisation Calendaromatic
organisation FlutterBridge
organisation Advanced DNS Security Advanced URL Filtering
organisation DNS Security
organisation Behavioral Threat Protection
organisation the Local Analysis
organisation the Investigation Cortex’s
organisation User Interaction
organisation UI
organisation Supported FlutterShell Commands Analysis
organisation write_pdf  read_pdf_dir  pdf_exists
organisation get_pdf_dir Read
organisation API
organisation Execute Command
organisation File Reading read_file
organisation File Writing
organisation Dir Enumeration
organisation Get Home Directory get_home_dir
organisation PACIFIC TRADE SOLUTIONS LTD
organisation Recipe Lister
Tactical Metrics
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product