INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Operation FlutterBridge Malicious Backdoor Spreads
| 2026-06-02 10:00 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The FlutterShell malware has been linked to a widespread operation known as Operation FlutterBridge, which targets macOS users through an extensive Google Ads campaign. This cluster of activity began in 2023 and continues to this day, with the attackers using malvertising campaigns to spread malicious payloads via separate operations such as RecipeLister and Calibre. The payload delivers FlutterShell, infecting targets with adware that exfiltrates data through artificial intelligence summarization features. As a result, these companies appear to be legitimate Ukraine and UK-based enterprises, registered years before the malicious activity started, but they are actually shell companies tied to Operation FlutterBridge.
Technical Mitigations AI-generated
• Implement a Web Application Firewall (WAF) to detect and block malicious traffic, including the use of IP blocking or rate limiting.
• Utilize cloud-based security services such as Google Cloud Security Command Center or AWS Shield to monitor and protect against FlutterShell attacks.
• Configure macOS operating system settings to limit the execution of arbitrary JavaScript code through web views.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
021666••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
48047c••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
8421c9••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b60074••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
co•••••.read
co•••••.podcastslounge
or•••••.sparkle
co•••••.app
ch•••••.js
up•••••.html
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign InfrastructureCampaign InfrastructureCampaign Background
CLCampaign Background
CLCampaign Spreads NewCampaign Spreads NewOperation FlutterBridgeOperation FlutterBridge
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
FIVE_EYES
FIVE_EYES
DACH
DACH
Incident Timeline
late 2025
Threat actors used fake Google Ads to target PodcastsLounge, a macOS app.
Click on any entity below to view its context and source!
campaign
Operation FlutterBridge
In late 2025, the attackers expanded their operations with Operation FlutterBridge, deploying a new macOS backdoor identified as FlutterShell.
infrastructure
Macos
In late 2025, the attackers expanded their operations with Operation FlutterBridge, deploying a new macOS backdoor identified as FlutterShell.
organisation
PodcastsLounge
In their latest scam, researchers caught three different versions between late 2025 and February 2026:
Version 1: An app called PodcastsLounge.
general_metric
1 Version
In their latest scam, researchers caught three different versions between late 2025 and February 2026:
Version 1: An app called PodcastsLounge.
early 2025
Threat actors used fake Google Ads to target macOS users.
Click on any entity below to view its context and source!
campaign
Campaign Infrastructure
FlutterShell browser hijacking activity, as seen in Cortex XDR.
CL-CRI-1089: Campaign Infrastructure and Evolving Tradecraft
We examined the evolution of CL-CRI-1089’s tactics and tradecraft across multiple campaigns since early 2025.
organisation
Cortex XDR
FlutterShell browser hijacking activity, as seen in Cortex XDR.
CL-CRI-1089: Campaign Infrastructure and Evolving Tradecraft
We examined the evolution of CL-CRI-1089’s tactics and tradecraft across multiple campaigns since early 2025.
organisation
CL-CRI-1089: Campaign Infrastructure
FlutterShell browser hijacking activity, as seen in Cortex XDR.
CL-CRI-1089: Campaign Infrastructure and Evolving Tradecraft
We examined the evolution of CL-CRI-1089’s tactics and tradecraft across multiple campaigns since early 2025.
organisation
CL-CRI-1089’s
FlutterShell browser hijacking activity, as seen in Cortex XDR.
CL-CRI-1089: Campaign Infrastructure and Evolving Tradecraft
We examined the evolution of CL-CRI-1089’s tactics and tradecraft across multiple campaigns since early 2025.
August 2025
Threat actors used Apple systems to target users with the JSCoreRunner campaign, which included a fake Google Ads targeting strategy.
Click on any entity below to view its context and source!
organisation
FileRipple
However, from August 2025, the network shifted to Apple systems with a campaign known as JSCoreRunner, also called FileRipple.
organisation
Apple
However, from August 2025, the network shifted to Apple systems with a campaign known as JSCoreRunner, also called FileRipple.
late August 2025
Threat actors used fake Google Ads to target macOS devices in the late August 2025 incident.
Click on any entity below to view its context and source!
organisation
Palo Alto Networks Unit
According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed
JSCoreRunner
(aka
FileRipple
) in late August 2025.
January 19, 2026
Threat actors used Fake Google Ads to target macOS devices on January 19, 2026.
February 2026
Researchers discovered that PodcastsLounge used fake Google ads to spread the macOS backdoor FlutterShell.
Click on any entity below to view its context and source!
organisation
PodcastsLounge
In their latest scam, researchers caught three different versions between late 2025 and February 2026:
Version 1: An app called PodcastsLounge.
general_metric
1 Version
In their latest scam, researchers caught three different versions between late 2025 and February 2026:
Version 1: An app called PodcastsLounge.
early February 2026
Threat actors used fake Google Ads to target Windows operating systems.
Click on any entity below to view its context and source!
infrastructure
Windows
However, up to early February 2026 the Windows versions did not appear to contain any embedded malicious logic.
March 2026
Threat actors used fake Google Ads to target macOS devices.
2026/06/02
The attackers used fake Google Ads to spread the macOS backdoor called FlutterShell, which was initially launched through a legitimate podcast player application named PodcastsLounge.
Click on any entity below to view its context and source!
organisation
LTD
Fake Businesses Defeating Ad Safety
To spread this Mac version, scammers used fake UK and Ukraine-based companies like AdsParkPro LTD and Advantage Web Marketing LLC.
Verified Shell Entities
Verified Google Ads accounts were the primary distribution vehicle for FlutterShell in this campaign, using verified shell companies AdsParkPro LTD and Advantage Web Marketing LLC.
organisation
Mac
Fake Businesses Defeating Ad Safety
To spread this Mac version, scammers used fake UK and Ukraine-based companies like AdsParkPro LTD and Advantage Web Marketing LLC.
infrastructure
Macos
Target audiences for these ads are macOS users in the U.S., Canada, Australia, France, and Germany.
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor.
Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor.
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called
FlutterShell
.
Executive Summary
We are tracking an increasingly widespread malvertising campaign targeting macOS.
This article provides a technical overview of the FlutterShell macOS malware and the delivery network behind the malvertising campaigns.
The attackers behind this cluster are responsible for spreading malicious payloads via
malvertising
campaigns, targeting both Windows and macOS users through separate, ongoing operations.
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
Overview of the FlutterShell Malware
FlutterShell is a macOS backdoor developed using the
Flutter framework
and designed to masquerade as legitimate software.
Figure 1 shows two of the applications on macOS hosts.
We also encountered versions of these macOS applications that did not contain any malicious code.
The absence of malicious code in both the macOS and Windows applications may suggest a phased deployment strategy, a technique designed to bypass automated detection.
The CL-CRI-1089 Connection
By pivoting on infrastructure related to the ad-filled intermediary site used in the FlutterShell campaign, we linked the current macOS campaign to two Windows malware strains:
RecipeLister
and
Calendaromatic
.
As the attackers behind CL-CRI-1089 continue to refine their JavaScript-to-native bridge techniques, we expect to see this architecture deployed in future campaigns targeting both macOS and Windows environments.
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
FlutterShell’s Update Mechanism via the Sparkle Framework
The FlutterShell backdoor uses the
Sparkle
software update framework for macOS applications in its update mechanism.
Our analysis of this sequence reveals the following flow:
Callback reception
: The malware listens for the update completion signal in the function SparkleUpdateService:_handleMethodCall() marked as the string onUpdateCycleFinished from the native macOS layer.
We also saw that some variants of FlutterShell have the com.apple.security.files.downloads.read-write macOS entitlement, which gives the malware the capability to read and write to files in the user’s Downloads directory.
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads.
organisation
Target
Target audiences for these ads are macOS users in the U.S., Canada, Australia, France, and Germany.
organisation
Operation FlutterBridge
We designate this campaign Operation FlutterBridge, and we call the payload that it delivers FlutterShell.
Built using the Flutter framework, FlutterShell infects targets with adware via malicious desktop applications.
In this scam, called Operation FlutterBridge, cybercriminals are using fake Google search ads to lure Mac owners into downloading malware.
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called
FlutterShell
.
organisation
FlutterShell
We designate this campaign Operation FlutterBridge, and we call the payload that it delivers FlutterShell.
Built using the Flutter framework, FlutterShell infects targets with adware via malicious desktop applications.
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called
FlutterShell
.
When users search for tools, these ads pop up and download apps that look like podcast players or
PDF viewers
but carry a malicious program named FlutterShell.
organisation
Anglophone
Operation FlutterBridge targets a global audience through an extensive Google Ads campaign, with an emphasis on Anglophone and Western European markets, distributed via hundreds of Google-verified advertisements.
organisation
Spread macOS Backdoor.
Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor.
organisation
Google
In this scam, called Operation FlutterBridge, cybercriminals are using fake Google search ads to lure Mac owners into downloading malware.
We reported these advertisers to Google, which provided the following statement:
Malware has no place on our platforms, and we’ve suspended these advertiser accounts for violating our policies.
These campaigns distribute malicious Google and YouTube advertisements using a network of Google-verified shell companies, with the ads acting as a lure to trick targets into deploying malware that masquerades as legitimate desktop applications.
infrastructure
Windows
The attackers behind this cluster are responsible for spreading malicious payloads via
malvertising
campaigns, targeting both Windows and macOS users through separate, ongoing operations.
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
The absence of malicious code in both the macOS and Windows applications may suggest a phased deployment strategy, a technique designed to bypass automated detection.
The CL-CRI-1089 Connection
By pivoting on infrastructure related to the ad-filled intermediary site used in the FlutterShell campaign, we linked the current macOS campaign to two Windows malware strains:
RecipeLister
and
Calendaromatic
.
As the attackers behind CL-CRI-1089 continue to refine their JavaScript-to-native bridge techniques, we expect to see this architecture deployed in future campaigns targeting both macOS and Windows environments.
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
The Windows activity was previously tracked by other vendors under the broader “TamperedChef” designation, before Unit 42 researchers
deconstructed
the activity into distinct clusters.
We also noted that the attackers behind CL-CRI-1089 offered Windows versions for all FlutterShell applications.
We also observed that this cluster used a different shell entity called SOFT WE ART LIMITED in past Windows campaigns.
Advantage Web Marketing LLC has been
observed
not only spreading malicious advertisements but also acting as the signatory for Windows adware variants associated with the CL-CRI-1089 cluster.
Connecting the Dots Behind CL-CRI-1089 Campaigns
This section details the connection between FlutterShell and the two Windows malware strains operated by the attackers behind CL-CRI-1089, and the strong links between FlutterShell and its predecessor JSCoreRunner.
The JSCoreRunner Connection
In addition to its connection with Windows-based campaigns, our analysis identified significant links between FlutterShell and the previously documented
JSCoreRunner
(also known as FileRipple).
UI Manipulation
close_webview
,
setSize
Resize the application’s windows, likely to reduce user suspicion.
This group previously used malvertising to target Windows users with fake programs called RecipeLister and Calendaromatic.
Attack execution (Source: Palo Alto Networks)
Researchers further noted that the network also used a shell company named SOFT WE ART LIMITED for their past Windows attacks.
What's more, Advantage Web Marketing LLC has been observed not only spreading malicious ads but also acting as the signatory for Windows adware variants associated with the cluster.
organisation
Operations
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
"
Operations attributed to CL-CRI-1089 also include
Recipe Lister
and
Calendaromatic
, both of which fall under a broader designation known as
TamperedChef
(aka
EvilAI
), an ongoing series of campaigns that involve using trojanized versions of productivity software to deliver potentially unwanted programs (PUPs) and adware.
organisation
Calendaromatic
Windows
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
organisation
The CL-CRI-1089 Connection
The CL-CRI-1089 Connection
By pivoting on infrastructure related to the ad-filled intermediary site used in the FlutterShell campaign, we linked the current macOS campaign to two Windows malware strains:
RecipeLister
and
Calendaromatic
.
infrastructure
Linux
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
organisation
FlutterShell’s Update Mechanism
FlutterShell’s Update Mechanism via the Sparkle Framework
The FlutterShell backdoor uses the
Sparkle
software update framework for macOS applications in its update mechanism.
organisation
FlutterShell Backdoor Spreads
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads.
organisation
Malicious Google
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads.
organisation
PDF
When users search for tools, these ads pop up and download apps that look like podcast players or
PDF viewers
but carry a malicious program named FlutterShell.
FlutterShell Deployment and Masquerading
We encountered three versions of FlutterShell in which the malware posed as a podcast player and two different PDF viewers.
organisation
TamperedChef
The Windows activity was previously tracked by other vendors under the broader “TamperedChef” designation, before Unit 42 researchers
deconstructed
the activity into distinct clusters.
"
Operations attributed to CL-CRI-1089 also include
Recipe Lister
and
Calendaromatic
, both of which fall under a broader designation known as
TamperedChef
(aka
EvilAI
), an ongoing series of campaigns that involve using trojanized versions of productivity software to deliver potentially unwanted programs (PUPs) and adware.
organisation
CL-CRI-1089
We also noted that the attackers behind CL-CRI-1089 offered Windows versions for all FlutterShell applications.
"
Operations attributed to CL-CRI-1089 also include
Recipe Lister
and
Calendaromatic
, both of which fall under a broader designation known as
TamperedChef
(aka
EvilAI
), an ongoing series of campaigns that involve using trojanized versions of productivity software to deliver potentially unwanted programs (PUPs) and adware.
Timeline and Versions
Behind this campaign is a cybercrime network called CL-CRI-1089, which research reveals has been active since at least 2023.
organisation
The JSCoreRunner Connection
In
The JSCoreRunner Connection
In addition to its connection with Windows-based campaigns, our analysis identified significant links between FlutterShell and the previously documented
JSCoreRunner
(also known as FileRipple).
organisation
FileRipple
The JSCoreRunner Connection
In addition to its connection with Windows-based campaigns, our analysis identified significant links between FlutterShell and the previously documented
JSCoreRunner
(also known as FileRipple).
organisation
UI Manipulation
UI Manipulation
close_webview
,
setSize
Resize the application’s windows, likely to reduce user suspicion.
organisation
XSIAM
Cortex XDR and XSIAM
Cortex XDR and XSIAM help to prevent the threats described in this article, by employing the Malware Prevention Engine.
organisation
Palo Alto Networks
FlutterShell disguised as a genuine podcast player and PDF viewer application (Source: Palo Alto Networks)
Attack Details and Malware Analysis
FlutterShell acts like a mini
web browser,
loading malicious code directly from the internet.
organisation
WebView
FlutterShell’s authors implemented a
WebView-based architecture
that utilizes a JavaScript-to-native bridge.
"All observed samples were signed with valid Apple Developer IDs and successfully passed notarization, meaning Apple's automated security checks did not flag them as malicious at the time of submission."
What makes FlutterShell noteworthy is that it implements a WebView-based architecture that utilizes a JavaScript-to-native bridge, thereby allowing the adversary to host malicious logic on an external website, rather than embedding it into the binary.
organisation
HTML
Figure 6 shows the HTML page presented to the targeted end-user, followed by the subsequent JavaScript code executed by the payload.
organisation
Apple Developer
"All observed samples were signed with valid Apple Developer IDs and successfully passed notarization, meaning Apple's automated security checks did not flag them as malicious at the time of submission."
What makes FlutterShell noteworthy is that it implements a WebView-based architecture that utilizes a JavaScript-to-native bridge, thereby allowing the adversary to host malicious logic on an external website, rather than embedding it into the binary.
All observed samples were signed with valid Apple Developer IDs and successfully passed notarization, meaning Apple's automated security checks did not flag them as malicious at the time of submission.
organisation
Apple
"All observed samples were signed with valid Apple Developer IDs and successfully passed notarization, meaning Apple's automated security checks did not flag them as malicious at the time of submission."
What makes FlutterShell noteworthy is that it implements a WebView-based architecture that utilizes a JavaScript-to-native bridge, thereby allowing the adversary to host malicious logic on an external website, rather than embedding it into the binary.
All observed samples were signed with valid Apple Developer IDs and successfully passed notarization, meaning Apple's automated security checks did not flag them as malicious at the time of submission.
organisation
Timeline
Timeline and Versions
Behind this campaign is a cybercrime network called CL-CRI-1089, which research reveals has been active since at least 2023.
organisation
File
Hash:
021666417de8b9972c179783fe60d4c4ad2d93224e3a0f16137065c960b1b845
File name:
PodcastsLounge.dmg
File description: Disk Image (DMG) installer for the malicious PodcastsLounge application
Hash:
363923500ce942bf1a953e8a4e943fbf1fb1b5ed6e5d247964c345b3ad5bfc34
File name:
podcasts_lounge.app
Bundle ID:
com.app.podcastsLounge
Developer ID:
organisation
FW9NHQ8922
Hash:
9053e8ddaecca1f960c041c944ca8799fc71dc86a4b50d2639ee4e0d2cb82f47
File name:
PDF-Brain.app
Bundle ID:
com.app.pdfBrain
Developer ID:
Batuhan Dabag (FW9NHQ8922)
File description: Main application executable for PDF-Brain
Hash:
b60074d1ea2008a581f432f2dee5f84f78668d9dd8e66f75d03c42dabd89bdea
File description: Dynamic library (dylib) associated with the PDF-Brain application.
organisation
Sparkle
Installation verification
: If the update completed without errors, the code checks for the existence of the Sparkle installation directory: $HOME/Library/Caches/com.app.[appname]/org.sparkle-project.
organisation
HOME/Library/Caches
Installation verification
: If the update completed without errors, the code checks for the existence of the Sparkle installation directory: $HOME/Library/Caches/com.app.[appname]/org.sparkle-project.
organisation
YouTube
These campaigns distribute malicious Google and YouTube advertisements using a network of Google-verified shell companies, with the ads acting as a lure to trick targets into deploying malware that masquerades as legitimate desktop applications.
CL-CRI-1089 Ads Delivery Network
Our investigation tracked the activity cluster CL-CRI-1089 through a far-reaching network of Google and YouTube advertisements, both of which are controlled by Google Ads.
These shell businesses had no real history but successfully bought hundreds of Google and YouTube ads.
organisation
Google Chrome
Upon execution, the malware modifies Google Chrome configuration files to hijack the browser, forcing all traffic through an attacker-controlled, ad-filled intermediary site.
"Upon execution, the malware modifies Google Chrome configuration files to hijack the browser, forcing all traffic through an attacker-controlled, ad-filled intermediary site," researchers Ido Asher, Noa Dekel, and Tom Fakterman said.
organisation
FlutterShell Deployment and
FlutterShell Deployment and Masquerading
We encountered three versions of FlutterShell in which the malware posed as a podcast player and two different PDF viewers.
organisation
VirusTotal
At the time of analysis, all three applications containing FlutterShell had zero detections on VirusTotal, as shown in Figure 3 for the PodcastsLounge application.
organisation
PodcastsLounge
At the time of analysis, all three applications containing FlutterShell had zero detections on VirusTotal, as shown in Figure 3 for the PodcastsLounge application.
"
Three different variants of FlutterShell, viz., PodcastsLounge, PDF-Brain, and PDF-Ninja, have been identified.
organisation
PDF-Brain
"
Three different variants of FlutterShell, viz., PodcastsLounge, PDF-Brain, and PDF-Ninja, have been identified.
The first variant masqueraded as a podcast app named PodcastsLounge while the subsequent variants appeared as PDF viewers named PDF-Brain and PDF-Ninja.
Version 2: A program called PDF-Brain.
organisation
PDF-
"
Three different variants of FlutterShell, viz., PodcastsLounge, PDF-Brain, and PDF-Ninja, have been identified.
The first variant masqueraded as a podcast app named PodcastsLounge while the subsequent variants appeared as PDF viewers named PDF-Brain and PDF-Ninja.
Version 3: An app named PDF-Ninja, which used a feature called –obfuscate to scramble its code.
organisation
FlutterShell Technical Analysis
FlutterShell Technical Analysis
FlutterShell’s Malicious WebView Architecture
The FlutterShell backdoor logic is not hardcoded into the binary.
organisation
/getUpdateThanksConfig
We also noticed that
/getUpdateThanksConfig
contained setup functions for commands that were not yet implemented in the FlutterShell binary.
organisation
Descriptive
Descriptive naming
(e.g:
read_file
,
write_file
)
organisation
/bin/sh
Deceptive naming
(e.g:
read_pdf
,
write_pdf
)
String Storage
(
/bin/sh
)
organisation
Binary Obfuscation
None
None
Flutter
Plaintext
Base64-encoded
Plaintext (regression)
Binary Obfuscation
None
None
Flutter
--obfuscate
enabled
C2 Domain
atsheisdomestic[.]org
etoftheappyrince[.]org
healightejustb[.]org
Table 1.
organisation
etoftheappyrince[.]org
healightejustb[.]org
Plaintext
Base64-encoded
Plaintext (regression)
Binary Obfuscation
None
None
Flutter
--obfuscate
enabled
C2 Domain
atsheisdomestic[.]org
etoftheappyrince[.]org
healightejustb[.]org
Table 1.
organisation
FlutterShell’s Adware Payload
FlutterShell’s Adware Payload
organisation
sinterfumesco[.]com
FlutterShell modifies the
default_search_provider_data
block within this file, specifically changing the
url
and
new_tab_url
values to the attacker-controlled domain
sinterfumesco[.]com
.
organisation
Secure Preferences
organisation
CL-CRI-1089 Ads Delivery Network
CL-CRI-1089 Ads Delivery Network
Our investigation tracked the activity cluster CL-CRI-1089 through a far-reaching network of Google and YouTube advertisements, both of which are controlled by Google Ads.
organisation
Verified Shell Entities
Verified Shell Entities
Verified Google Ads accounts were the primary distribution vehicle for FlutterShell in this campaign, using verified shell companies AdsParkPro LTD and Advantage Web Marketing LLC.
organisation
the Google Ads Transparency Center
Figure 10 shows advertisements by Advantage Web Marketing LLC in the Google Ads Transparency Center.
organisation
Calendaromatic
In the case of the RecipeLister and Calendaromatic malware strains, the actor encoded content within hidden characters or date synonyms.
organisation
FlutterBridge
Up until late March, we continued to witness the distribution of FlutterBridge malware variants.
organisation
Advanced DNS Security
Advanced URL Filtering
Advanced URL Filtering and Advanced DNS Security
Advanced URL Filtering
and
Advanced DNS Security
identify known domains and URLs associated with this activity as malicious.
organisation
DNS Security
Advanced URL Filtering and Advanced DNS Security
Advanced URL Filtering
and
Advanced DNS Security
identify known domains and URLs associated with this activity as malicious.
organisation
Behavioral Threat Protection
This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, to prevent both known and unknown malware from causing harm to endpoints.
organisation
the Local Analysis
This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, to prevent both known and unknown malware from causing harm to endpoints.
organisation
the Investigation
Cortex’s
How the Agentic Assistant Supported the Investigation
Cortex’s
AgentiX
Agentic Assistant streamlined the investigation by allowing the team to query the data using natural language, providing deeper context and insights, and suggesting clear recommendations on what should be done next.
organisation
User Interaction
User Interaction:
When the targeted user clicks the About or Update buttons in the application settings.
organisation
UI
In a legitimate implementation, once Sparkle finishes downloading an update to the cache, it triggers a user interface (UI) prompt, such as “A new version is available.
organisation
Supported FlutterShell Commands Analysis
Supported FlutterShell Commands Analysis
FlutterShell’s built-in commands provide full backdoor capabilities, allowing the attackers to execute shell commands and manipulate files on the system.
organisation
write_pdf
read_pdf_dir
pdf_exists
Category
Commands and Features
Description
Variant
PodcastsLounge
PDF-Brain
PDF-Ninja
Execution
exec_sync
pdf_sync
renderPDF
Executes arbitrary shell commands with current user permissions
Filesystem
read_file
write_file
read_dir
exists
get_home_dir
read_pdf
write_pdf
read_pdf_dir
pdf_exists
get_pdf_dir
Read files
Write files
Get directory structure
Harvesting
get_env
Extracts environment variables.
organisation
get_pdf_dir
Read
Category
Commands and Features
Description
Variant
PodcastsLounge
PDF-Brain
PDF-Ninja
Execution
exec_sync
pdf_sync
renderPDF
Executes arbitrary shell commands with current user permissions
Filesystem
read_file
write_file
read_dir
exists
get_home_dir
read_pdf
write_pdf
read_pdf_dir
pdf_exists
get_pdf_dir
Read files
Write files
Get directory structure
Harvesting
get_env
Extracts environment variables.
organisation
API
These may contain high-value assets like plaintext API keys for secondary access.
organisation
Execute Command
Capability
FlutterShell
JSCoreRunner
Check File/Dir Existence
exists/existsSync
_fsExistsSync
Execute Command
exec_sync/pdf_sync
_execSync
File Reading
read_file
_fsReadFileSync
File Writing
write_file
_fsWriteFileSync
Dir Enumeration
read_dir
_fsReaddirSync
Get Home Directory
get_home_dir
_osHomedir
Table 3.
organisation
File Reading
read_file
Capability
FlutterShell
JSCoreRunner
Check File/Dir Existence
exists/existsSync
_fsExistsSync
Execute Command
exec_sync/pdf_sync
_execSync
File Reading
read_file
_fsReadFileSync
File Writing
write_file
_fsWriteFileSync
Dir Enumeration
read_dir
_fsReaddirSync
Get Home Directory
get_home_dir
_osHomedir
Table 3.
organisation
File Writing
Capability
FlutterShell
JSCoreRunner
Check File/Dir Existence
exists/existsSync
_fsExistsSync
Execute Command
exec_sync/pdf_sync
_execSync
File Reading
read_file
_fsReadFileSync
File Writing
write_file
_fsWriteFileSync
Dir Enumeration
read_dir
_fsReaddirSync
Get Home Directory
get_home_dir
_osHomedir
Table 3.
organisation
Dir Enumeration
Capability
FlutterShell
JSCoreRunner
Check File/Dir Existence
exists/existsSync
_fsExistsSync
Execute Command
exec_sync/pdf_sync
_execSync
File Reading
read_file
_fsReadFileSync
File Writing
write_file
_fsWriteFileSync
Dir Enumeration
read_dir
_fsReaddirSync
Get Home Directory
get_home_dir
_osHomedir
Table 3.
organisation
Get Home Directory
get_home_dir
Capability
FlutterShell
JSCoreRunner
Check File/Dir Existence
exists/existsSync
_fsExistsSync
Execute Command
exec_sync/pdf_sync
_execSync
File Reading
read_file
_fsReadFileSync
File Writing
write_file
_fsWriteFileSync
Dir Enumeration
read_dir
_fsReaddirSync
Get Home Directory
get_home_dir
_osHomedir
Table 3.
organisation
PACIFIC TRADE SOLUTIONS LTD
Some of the front companies are
AdsParkPro LTD
,
Advantage Web Marketing LLC
, and
SOFT WE ART LIMITED
(now PACIFIC TRADE SOLUTIONS LTD).
organisation
Recipe Lister
FlutterShell has also been found to share technical similarities with
Calendaromatic
and Recipe Lister, the most obvious being the WebView-based code architecture to facilitate dynamic payload changes.
Tactical Metrics
Metrics
infrastructure
Macos
Affected Product
Click for context!
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor.
Executive Summary
We are tracking an increasingly widespread malvertising campaign targeting macOS.
This article provides a technical overview of the FlutterShell macOS malware and the delivery network behind the malvertising campaigns.
The attackers behind this cluster are responsible for spreading malicious payloads via
malvertising
campaigns, targeting both Windows and macOS users through separate, ongoing operations.
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
In late 2025, the attackers expanded their operations with Operation FlutterBridge, deploying a new macOS backdoor identified as FlutterShell.
Overview of the FlutterShell Malware
FlutterShell is a macOS backdoor developed using the
Flutter framework
and designed to masquerade as legitimate software.
Figure 1 shows two of the applications on macOS hosts.
We also encountered versions of these macOS applications that did not contain any malicious code.
The absence of malicious code in both the macOS and Windows applications may suggest a phased deployment strategy, a technique designed to bypass automated detection.
The CL-CRI-1089 Connection
By pivoting on infrastructure related to the ad-filled intermediary site used in the FlutterShell campaign, we linked the current macOS campaign to two Windows malware strains:
RecipeLister
and
Calendaromatic
.
As the attackers behind CL-CRI-1089 continue to refine their JavaScript-to-native bridge techniques, we expect to see this architecture deployed in future campaigns targeting both macOS and Windows environments.
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
FlutterShell’s Update Mechanism via the Sparkle Framework
The FlutterShell backdoor uses the
Sparkle
software update framework for macOS applications in its update mechanism.
…this sequence reveals the following flow:
Callback reception
: The malware listens for the update completion signal in the function SparkleUpdateService:_handleMethodCall() marked as the string onUpdateCycleFinished from the native macOS layer.
We also saw that some variants of FlutterShell have the com.apple.security.files.downloads.read-write macOS entitlement, which gives the malware the capability to read and write to files in the user’s Downloads directory.
Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor.
Target audiences for these ads are macOS users in the U.S., Canada, Australia, France, and Germany.
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads.
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called
FlutterShell
.
Metrics
infrastructure
Windows
Affected Product
The attackers behind this cluster are responsible for spreading malicious payloads via
malvertising
campaigns, targeting both Windows and macOS users through separate, ongoing operations.
Operations attributed to this cluster include the
RecipeLister
and
Calendaromatic
Windows campaigns, as well as the
JSCoreRunner
macOS campaign.
The Windows activity was previously tracked by other vendors under the broader “TamperedChef” designation, before Unit 42 researchers
deconstructed
the activity into distinct clusters.
We also noted that the attackers behind CL-CRI-1089 offered Windows versions for all FlutterShell applications.
However, up to early February 2026 the Windows versions did not appear to contain any embedded malicious logic.
The absence of malicious code in both the macOS and Windows applications may suggest a phased deployment strategy, a technique designed to bypass automated detection.
We also observed that this cluster used a different shell entity called SOFT WE ART LIMITED in past Windows campaigns.
Advantage Web Marketing LLC has been
observed
not only spreading malicious advertisements but also acting as the signatory for Windows adware variants associated with the CL-CRI-1089 cluster.
Connecting the Dots Behind CL-CRI-1089 Campaigns
This section details the connection between FlutterShell and the two Windows malware strains operated by the attackers behind CL-CRI-1089, and the strong links between FlutterShell and its predeces…
The CL-CRI-1089 Connection
By pivoting on infrastructure related to the ad-filled intermediary site used in the FlutterShell campaign, we linked the current macOS campaign to two Windows malware strains:
RecipeLister
and
Calendaromatic
.
The JSCoreRunner Connection
In addition to its connection with Windows-based campaigns, our analysis identified significant links between FlutterShell and the previously documented
JSCoreRunner
(also known as FileRipple).
As the attackers behind CL-CRI-1089 continue to refine their JavaScript-to-native bridge techniques, we expect to see this architecture deployed in future campaigns targeting both macOS and Windows environments.
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
UI Manipulation
close_webview
,
setSize
Resize the application’s windows, likely to reduce user suspicion.
This group previously used malvertising to target Windows users with fake programs called RecipeLister and Calendaromatic.
Attack execution (Source: Palo Alto Networks)
Researchers further noted that the network also used a shell company named SOFT WE ART LIMITED for their past Windows attacks.
What's more, Advantage Web Marketing LLC has been observed not only spreading malicious ads but also acting as the signatory for Windows adware variants associated with the cluster.
Metrics
infrastructure
Linux
Affected Product
The mitigation methods implement malware protection based on the different operating systems – Windows, macOS and Linux.
Intelligence Sources
HackRead
2026-06-08
The Hacker News
2026-06-04
Palo Alto
2026-06-02
Palo Alto
2026-06-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
76x
organisation
Identified Entity
Operation FlutterBridge
entity
9x
timeline
Temporal Reference
January 19, 2026
date
6x
target region
Target Country
Ukraine
country
4x
campaign
Campaign
Operation FlutterBridge
operation
4x
tactic
MITRE ATT&CK Technique
T1583.008 - Malvertising
technique
3x
infrastructure
Affected Product
Macos
software
3x
general metric
Version
1
version
3x
attribution
Attributing Entity
the Google Ads Transparency Center
authority
2x
source region
Origin Country
United Kingdom
country
2x
industry
Targeted Sector
Legal
sector
2x
general metric
Second
600
second
2x
general metric
Minute
10
minute
Contextual Telemetry
Context Block
2 METRICS
tactic
Cyber Operation Type
Exfiltration
tactic
general metric
Researchers
42
researchers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.