FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

Jun 4, 2026

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell.

According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the two attack chains is

Get Free Report & Network Analysis

Please check your email for the free report.