Operation FlutterBridge: The FlutterShell macOS Backdoor

Reported 19 Jun 2026 by otx · Severity: medium

FlutterShell is a macOS backdoor campaign active from December 2025 to March 2026, identified as cluster CL-CRI-1089 under Operation FlutterBridge. The threat actors deliberately misused the Flutter framework to deliver malware through malvertising campaigns on Google and YouTube