Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor

2026-06-08T20:51:44Z7e8f1bc043d565b9024bb16de90066a6a300aa650e67f7b51f314769ff37ba55
FlutterShellInstagramMFA-bypassMiasma','github-compromiseMicrosoft 365RemusStealeraccount-takeoverbackdoorbotnetcloud-theftcrypto-clipperdata-leakfake-adsfast-fluxlaw-firmsloadermacOSmalwarenpmpassword-resetprivacy-leakransomsite-cloningsupply-chainvishing

What happened

Multiple active threats reported: Operation “FlutterBridge” uses fake Google ads and shell companies to distribute a new macOS backdoor named FlutterShell. Attackers are cloning legitimate developer tool sites (Ghidra, dnSpy, ILSpy) to serve malware (RemusStealer, crypto clippers, loaders). Silent Ransom Group leverages a fast-flux botnet to hide data-leak sites while targeting law firms. Instagram experienced a recovery-tool bug exposing 20,225 accounts to password-reset abuse and an additional glitch leaked contact info (including Mark Zuckerberg). Pink Extortion Group conducts vishing to ph

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
7e8f1bc043d565b9024bb16de90066a6a300aa650e67f7b51f314769ff37ba55
Enrichment time
2026-06-08T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor · Baitaphish