Operation FlutterBridge: The FlutterShell macOS Backdoor
June 19, 2026, 8:39 a.m.
Description
FlutterShell is a macOS backdoor campaign active from December 2025 to March 2026, identified as cluster CL-CRI-1089 under Operation FlutterBridge. The threat actors deliberately misused the Flutter framework to deliver malware through malvertising campaigns on Google and YouTube. The malware employs a two-component architecture: a thin Mach-O launcher and a large Flutter payload dylib. Across three generations, the operators rotated Apple Developer certificates, implemented progressive Dart obfuscation, and renamed bridge commands to evade detection. The backdoor uses a WKWebView to load attacker-controlled JavaScript from C2 servers, implementing a conditional execution model where commands are delivered at runtime via a JavaScript-to-native bridge called flutterInvoke. The primary impact includes Chrome browser hijacking to inject sinterfumesco[.]com as the default search provider and persistent infection through silent Sparkle framework updates.
Tags
Date
- Created: June 19, 2026, 12:03 a.m.
- Published: June 19, 2026, 12:03 a.m.
- Modified: June 19, 2026, 8:39 a.m.
Indicators
- bf90fb31e6024d7e6616f5acd0e8aa28738a9095a508c1a986e1e974cb9e79a0
- cc4f048e66c5ab3c0f1d767bb8fc464d082641f4888ea3cd14ea3775077c4bf2
- 134517796178a150a1585672be134169d6877082b598d840baa3f37b0222be26
- 2c5bc9e95e1e9b73e3ba8870a008802899866a2c0e2e10112aefddf7a96af04e
- 32da1437a2734224406c7e5e8d756f0c0cd58c0c959478571cbfc0cd564d018a
- fc091ddb4d845280aeb7745cfdb6b7cb0013abc35db9e634f055b8e8fb0b5b1e
- 6c3f61d46d4de26b9cb16808bf17c33ae69f651a4b879e7b5612ff7f548e2a82
- f544bfab72d380cc20692d8ec9d31ea666785fe225dccd55beab29a3c0fdfad2
- 363923500ce942bf1a953e8a4e943fbf1fb1b5ed6e5d247964c345b3ad5bfc34
- https://healightejustb.org/welcome_page.js
- https://etoftheappyrince.org
- https://healightejustb.org/welcome_page.html
- https://atsheisdomestic.org/api/update-delay
- https://atsheisdomestic.org/api/subscribe
- https://atsheisdomestic.org/update-thanks.html
- https://healightejustb.org/api/central-config
- https://atsheisdomestic.org/api/podcasts
- https://healightejustb.org/summarize-text
- https://healightejustb.org/checkForNewVersion
- https://etoftheappyrince.org/...
- https://etoftheappyrince.org/api/pdfs
- https://etoftheappyrince.org/summarize-text
- https://etoftheappyrince.org/api/update-delay
- https://etoftheappyrince.org/update-thanks.html
Additional Informations
- atsheisdomestic.org
- etoftheappyrince.org
- event.process.parent.name
- sinterfumesco.com
- event.process.name
- healightejustb.org