CL-CRI-1089 is a cybercrime activity cluster tracked by Palo Alto Networks Unit 42 and assessed to be active since at least early 2023. The cluster is linked to large-scale malvertising operations targeting both Windows and macOS users. Reported campaigns and malware associated with this cluster include Operation FlutterBridge, JSCoreRunner (also referred to as FileRipple), and Windows-focused activity involving RecipeLister, Calendaromatic, DocuFlex, AppSuite PDF, and attacks described under the TamperedChef campaign umbrella. Some reporting also places this activity within broader TamperedChef/EvilAI-style operations. In its macOS activity, CL-CRI-1089 distributed FlutterShell through fake Google and YouTube ads promoting trojanized but functional applications such as PodcastsLounge, PDF-Brain, and PDF-Ninja. Unit 42 described FlutterShell as a Flutter-based backdoor with adware and browser-hijacking behavior. The malware used a WebView-based architecture and a JavaScript-to-native bridge (reported as flutterInvoke / flutterinvoke) to load attacker-controlled logic remotely, enabling dynamic behavior changes without updating the binary. Reported capabilities include arbitrary command execution, file system interaction, environment variable exfiltration, system fingerprinting via hardware UUID collection, LaunchAgent persistence, Sparkle-based silent replacement, and modification of Google Chrome Secure Preferences to redirect searches and new tabs to the attacker-controlled domain sinterfumesco.com. Some PDF-themed variants also included a fake AI summarization feature that uploaded victim documents to attacker-controlled servers. The cluster’s tradecraft includes large-scale malvertising, use of shell companies and verified advertiser accounts to buy ads, trojanized productivity software, legitimate code-signing certificates, and in some cases Apple Developer IDs that passed notarization. Reporting links parts of the cluster’s code-signing and corporate infrastructure to Ukrainian entities. Named shell companies associated in reporting include AdsParkPro LTD, Advantage Web Marketing LLC, and SOFT WE ART LIMITED. Known infrastructure reported for FlutterShell includes the domains atsheisdomestic.org, etoftheappyrince.org, and healightejustb.org.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated macOS malware activity using the FlutterShell family in Operation FlutterBridge, with browser search hijacking, C2-conditional execution via WKWebView and a JavaScript bridge, certificate rotation, obfuscation, and persistence mechanisms such as LaunchAgents and Sparkle-based bundle replacement.
Cybercrime network behind Operation FlutterBridge, using malvertising and fake Google ads to lure users into downloading trojanized applications. The group shifted from Windows-focused fake apps to Apple/macOS campaigns and deployed FlutterShell as a backdoor capable of browser hijacking, command execution, file interaction, and data exfiltration.
Financially motivated activity cluster behind a widespread malvertising campaign targeting Apple desktop ecosystems, evolving from adware distribution to a backdoor-capable operation using signed macOS apps, browser hijacking, remote WebView-based logic, command execution, data exfiltration, and filesystem manipulation.
Threat cluster behind the Operation FlutterBridge malvertising campaign distributing FlutterShell via malicious Google Ads for macOS applications, with links to earlier JSCoreRunner activity and Windows attacks under the TamperedChef campaign umbrella.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.