Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor
2026-06-08T20:51:44Z•7e8f1bc043d565b9024bb16de90066a6a300aa650e67f7b51f314769ff37ba55
FlutterShellInstagramMFA-bypassMiasma','github-compromiseMicrosoft 365RemusStealeraccount-takeoverbackdoorbotnetcloud-theftcrypto-clipperdata-leakfake-adsfast-fluxlaw-firmsloadermacOSmalwarenpmpassword-resetprivacy-leakransomsite-cloningsupply-chainvishing
What happened
Multiple active threats reported: Operation “FlutterBridge” uses fake Google ads and shell companies to distribute a new macOS backdoor named FlutterShell. Attackers are cloning legitimate developer tool sites (Ghidra, dnSpy, ILSpy) to serve malware (RemusStealer, crypto clippers, loaders). Silent Ransom Group leverages a fast-flux botnet to hide data-leak sites while targeting law firms. Instagram experienced a recovery-tool bug exposing 20,225 accounts to password-reset abuse and an additional glitch leaked contact info (including Mark Zuckerberg). Pink Extortion Group conducts vishing to ph
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 7e8f1bc043d565b9024bb16de90066a6a300aa650e67f7b51f314769ff37ba55
- Enrichment time
- 2026-06-08T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.