ctipilot.ch

Operation FlutterBridge

campaign · campaign:flutterbridge-cl-cri-1089

Operation FlutterBridge (CL-CRI-1089) — notarized macOS FlutterShell backdoor via Google Ads malvertising

Aliases: CL-CRI-1089

Coverage timeline
1
first 2026-06-05 → last 2026-06-05
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-05Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • thehackernews.com1 (50%)
  • unit42.paloaltonetworks.com1 (50%)

explore in graph

Entries about Operation FlutterBridge (1)

2026-06-05 · view entry permalink →

NOTABLE

Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature

Unit 42 details Operation FlutterBridge, the evolution of cluster CL-CRI-1089 (active since August 2025), which distributes macOS backdoors disguised as productivity apps (PodcastsLounge, PDF-Brain, PDF-Ninja) via hundreds of Google Ads bought through verified shell companies (Unit 42, 2026-06-02; The Hacker News, 2026-06-04). Every sample was signed with a valid Apple Developer ID and passed notarization, with zero VirusTotal detections at analysis time — Gatekeeper does not catch these. The FlutterShell payload keeps its malicious logic on an attacker-controlled website and uses a Flutter JavaScript-to-native bridge to translate JSON commands into native macOS calls, so capability changes need no new binary. Confirmed behaviour: arbitrary shell execution, file read/write, environment-variable theft, Chrome hijacking via the "Secure Preferences" file, and document exfiltration routed through the attacker's server under the guise of an AI document-summarisation feature. Targeting is global with explicit emphasis on Western Europe, including France and Germany.

Why it matters to us: notarization-bypassed, Developer-ID-signed macOS malware defeats the controls most teams lean on for Mac fleets. The reliable detection layer is behavioural: macOS endpoint telemetry for apps that instantiate a WKWebView with a custom JS message handler that then spawns shell processes, non-browser writes to Chrome's Secure Preferences, and outbound connections from "productivity" apps to CDN-fronted infrastructure.

threat05 Jun 05:00Zmulti-sourceOpen finding ↗