Malicious Ads Deliver FlutterShell Backdoor to macOS Systems
Key Takeaways A sophisticated malvertising campaign, dubbed “Operation FlutterBridge,” is actively targeting macOS users. Attackers are using malicious Google Ads to distribute trojanized...
Key Takeaways
- A sophisticated malvertising campaign, dubbed “Operation FlutterBridge,” is actively targeting macOS users.
- Attackers are using malicious Google Ads to distribute trojanized desktop applications that install the FlutterShell backdoor.
- FlutterShell is a powerful, dynamically loaded backdoor that grants full remote control and data exfiltration capabilities to threat actors.
- The malware disguises itself as legitimate apps, bypasses Apple’s notarization, and redirects browser traffic for ad revenue.
- Defenders should monitor for suspicious browser modifications and specific command executions to detect and mitigate infections.
Malicious Google Ads Deliver Potent FlutterShell Backdoor to macOS Systems
macOS users are currently at significant risk from an escalating malware campaign. Threat actors are leveraging Google Ads to promote deceptive desktop applications, which, once installed, secretly deploy a powerful backdoor onto compromised systems.
Table Of Content
This campaign, identified as “Operation FlutterBridge,” represents a notable advancement in tactics by financially motivated attackers who have been active since at least 2023. Researchers from Unit 42, Palo Alto Networks’ threat intelligence division, have been tracking this activity under the cluster CL-CRI-1089.
Understanding FlutterShell: A Stealthy and Dynamic Backdoor
The core of this operation is FlutterShell, a backdoor developed using Google’s Flutter framework. It is engineered to mimic legitimate applications while executing malicious code covertly in the background. Unlike more basic forms of malware, FlutterShell provides attackers with comprehensive remote control over infected machines, enabling them to run commands, manipulate files, and steal sensitive data. Unit 42’s report, shared with Cyber Security News (CSN), indicates that these attackers have been engaged in malvertising since 2023, with separate, ongoing campaigns targeting both Windows and macOS users.
A key characteristic of FlutterShell is its ingenious architecture, which avoids embedding malicious code directly within the application binary. Instead, the malware loads a remote webpage via an integrated WebView component. This webpage then delivers the attack logic as commands over a channel named flutterInvoke. This dynamic approach allows attackers to modify the malware’s functionality instantly without requiring an application update, making it highly adaptable and resilient to detection.
During their investigation, Unit 42 identified three distinct versions of FlutterShell. The initial variant masqueraded as a podcast player called PodcastsLounge. Subsequent versions appeared as PDF viewers, named PDF-Brain and PDF-Ninja. All three applications were fully functional, making it exceedingly difficult for users to discern their malicious nature. At the time of analysis, these applications had zero detections on VirusTotal and had successfully passed Apple’s notarization process, utilizing valid developer IDs.
Infection Chain and Post-Compromise Actions
Upon successful installation, FlutterShell first fingerprints the compromised machine. It then specifically targets Google Chrome, modifying its settings file to redirect all new tabs and search queries to an attacker-controlled website. This site is heavily loaded with advertisements, generating illicit revenue for the threat actors. The entire process occurs silently, without any user notification or warning.
The PDF-Brain and PDF-Ninja variants incorporate an additional insidious feature: an AI summarization function. This feature secretly routes document content through the attackers’ servers before returning the summarized results to the user, effectively exfiltrating sensitive information under the guise of providing a useful service.
The Evolving Infrastructure Behind CL-CRI-1089
The infrastructure supporting this sophisticated ad campaign revealed clear signs of fraud. The shell companies involved exhibited minimal online presence, utilized templated websites, and were ostensibly led by Ukrainian nationals with no verifiable professional history. Investigators discovered that these companies were registered approximately a year before their first ad expenditures, a tactic likely employed to “age” the accounts and circumvent early fraud detection mechanisms.
Operation FlutterBridge demonstrates a rapid adaptability from its operators. When one shell company, AdsParkPro LTD, was removed from Google Ads in January 2026, the attackers re-emerged just two weeks later under a newly verified account, deploying a fresh malware variant.
Analysis revealed that FlutterShell shares its core command structure with JSCoreRunner, a previously documented macOS malware. This includes shared functionalities for command execution, file reading, and directory listing. However, a critical distinction is FlutterShell’s dynamic retrieval of its logic, in contrast to JSCoreRunner’s static embedding, which significantly complicates detection efforts.
Google’s Response
Google confirmed that it suspended the advertiser accounts associated with this campaign after being notified by Unit 42. The malicious ads, crafted to appear legitimate, had reached a broad global audience, with a particular focus on English-speaking countries and Western European markets such as France and Germany.
What You Should Do
- Exercise Caution with Advertisements: Be highly suspicious of software downloads promoted via search engine ads, even for well-known applications. Always download software directly from official vendor websites.
- Verify Application Sources: Before installing any application, especially on macOS, verify the developer’s identity and ensure it comes from a trusted source.
- Monitor Browser Settings: Regularly check your browser’s default search engine and new tab settings for any unauthorized changes.
- Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to monitor for suspicious command executions, particularly those involving
IOPlatformUUID, and unexpected Chrome process restarts with custom launch arguments. - Block Known Indicators of Compromise (IoCs): Update your network firewalls and security tools with the provided IoCs, including C2 domains and SHA256 hashes, to prevent communication with malicious infrastructure.
- User Awareness Training: Educate users about malvertising tactics, the risks of downloading software from unofficial sources, and how to identify suspicious behavior.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA256 | 021666417de8b9972c179783fe60d4c4ad2d93224e3a0f16137065c960b1b845 |
PodcastsLounge.dmg — DMG installer for malicious PodcastsLounge app |
| SHA256 | 363923500ce942bf1a953e8a4e943fbf1fb1b5ed6e5d247964c345b3ad5bfc34 |
podcasts_lounge.app — Main executable, Developer ID: Yasar Sever (UBZDAAV97Y) |
| SHA256 | 8421c902364980e3d762ec6dbbe6b0f40577c27bd79b48c57d098328b2533109 |
Dynamic library (dylib) associated with PodcastsLounge |
| SHA256 | 644fc49fa1006a2a2acace694e5fb83753164e2617051ece6d9dc9ea32329e70 |
PDF-Brain.dmg — DMG installer for malicious PDF-Brain app |
| SHA256 | 9053e8ddaecca1f960c041c944ca8799fc71dc86a4b50d2639ee4e0d2cb82f47 |
PDF-Brain.app — Main executable, Developer ID: Batuhan Dabag (FW9NHQ8922) |
| SHA256 | b60074d1ea2008a581f432f2dee5f84f78668d9dd8e66f75d03c42dabd89bdea |
Dynamic library (dylib) associated with PDF-Brain |
| SHA256 | 9425e8e39fa8a7212cdd07f0917cb3dfde38a90b87297de2c82a5850aff1e4de |
PDF-Ninja.dmg — DMG installer for malicious PDF-Ninja app |
| SHA256 | 30448686ec900d5213d74f08f0d2b7924c5336a29445b2a434aba8d8b19d7530 |
PDF-Ninja.app — Main executable, Developer ID: Yusuf Bal (B73CHZ24Y8) |
| SHA256 | 48047c34bbd57fe1e24bc538bc2ce9e0ac4c4eb48d3b0c195b414f0379dc0745 |
Dynamic library (dylib) associated with PDF-Ninja |
| Domain | atsheisdomestic[.]org |
PodcastsLounge C2 domain |
| URL | hxxps[:]//atsheisdomestic[.]org/update-thanks.html |
PodcastsLounge C2 payload URL |
| Domain | etoftheappyrince[.]org |
PDF-Brain C2 domain |
| URL | hxxps[:]//etoftheappyrince[.]org/update-delay |
PDF-Brain C2 delay endpoint |
| Domain | healightejustb[.]org |
PDF-Ninja C2 domain |
| URL | hxxps[:]//healightejustb[.]org/checkupdateTO.js |
PDF-Ninja C2 update script |
| Domain | sinterfumesco[.]com |
Attacker-controlled adware redirect site |
| Domain | ads-parkpro[.]com |
Website previously associated with AdsParkPro LTD |
| Domain | adsparkpro[.]top |
Website previously associated with AdsParkPro LTD |
| Domain | adsparkpro[.]net |
Website previously associated with AdsParkPro LTD |
| Domain | softwe[.]art |
Website associated with SOFT WE ART LIMITED |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.