Operation FlutterBridge is a malware campaign tracked as CL-CRI-1089 that targeted macOS users with a backdoor known as FlutterShell. Active from December 2025 through March 2026, the operation distributed trojanized applications masquerading as legitimate productivity software and leveraged malicious advertising on major search and video platforms to drive victims to fake download sites. The malware abused Google’s Flutter framework to make the launcher component resemble a normal cross-platform application while embedding a larger Dart-based payload library containing the malicious logic. FlutterShell used a command-and-control-conditional design in which the implanted application remained largely benign in sandboxed or offline analysis unless it received live instructions from attacker infrastructure. It employed a hidden WKWebView to retrieve JavaScript-delivered commands from remote servers, allowing operators to alter behavior server-side without changing the binary. Across multiple observed generations, the actor rotated certificates, infrastructure, and command names, including names chosen to resemble normal PDF-related functionality, indicating deliberate defense evasion. Observed post-compromise behavior included hardware fingerprinting, modification of Google Chrome settings to replace the default search engine, forced browser restart behavior intended to reduce user visibility, and persistence via abuse of the Sparkle update mechanism to quietly stage and install a replacement application bundle. The campaign demonstrated sustained operational maintenance through rapid retooling after certificate revocations and later use of self-signed signing material. High-confidence reporting supports characterization of Operation FlutterBridge as a macOS-focused intrusion cluster with capabilities spanning initial access, persistence, reconnaissance, post-exploitation, defense evasion, and browser-focused hijacking activity. Attribution to a specific nation state or criminal organization is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.