news.mlab.sh
Back to the feed
malware

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

High
Summary

Palo Alto Unit 42 is tracking ‘Operation FlutterBridge,’ a widespread malvertising campaign targeting macOS users. The campaign, a follow-up to the ‘JSCoreRunner’ campaign, utilizes malicious desktop applications built with the Flutter framework to deliver the FlutterShell backdoor, which includes adware and backdoor capabilities, including AI-powered data exfiltration. The attackers employ a network of shell companies to distribute ads via Google Ads, and Google has suspended the associated advertiser accounts.

Operation FlutterBridge represents the latest iteration of a cybercrime campaign originating in 2023, primarily targeting macOS users through malvertising. The core of the campaign utilizes FlutterShell, a macOS backdoor developed using the Flutter framework. This backdoor functions as adware, hijacking Google Chrome to route traffic through an attacker-controlled site filled with advertisements. However, FlutterShell’s capabilities extend beyond simple adware, offering attackers the ability to execute arbitrary commands, manipulate the file system, and exfiltrate environment variables. Recent analysis reveals that the malware is under active development, with ongoing improvements and new variants being integrated into the code. The attackers utilize a WebView-based architecture, hosting malicious logic on external websites to dynamically alter behavior without requiring recompilation.

Google has taken action against the campaign, suspending advertiser accounts that violated its policies. Unit 42 tracks this activity as CL-CRI-1089, alongside other related campaigns like JSCoreRunner and Windows campaigns such as RecipeLister and Calendaromatic. The attackers consistently employ a network of Google-verified shell companies to distribute malicious advertisements, tricking targets into deploying the malware. The ongoing development and adaptability of FlutterShell highlight the sophistication of the threat actors involved.

Read the full article at Palo Alto Unit 42