FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

Read full story on The Hacker News
Share
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
AI disclosure

Summary

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the two attack chains is

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.