Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A financially-motivated threat group designated CL-CRI-1089 is actively distributing a macOS backdoor called FlutterShell through malicious Google Ads, using fake applications that passed Apple’s notarization process and evaded major antivirus detections at the time of initial analysis. The malware’s architecture places all malicious logic on remote attacker-controlled servers, making it invisible to standard static analysis and endpoint security tools. Organizations with macOS fleets whose employees use Google search or download productivity applications face a credible, active risk of credential theft, document exfiltration, and persistent backdoor access.

Author

Tech Jacks Solutions