Skip to main content
Mallory
🇺🇦 UA6 malware families

CL-CRI-1089

Also known asCL-CRI-1089

CL-CRI-1089 is a cybercrime activity cluster tracked by Palo Alto Networks Unit 42 and assessed to have been active since at least early 2023. Unit 42 links this cluster to large-scale malvertising operations distributing trojanized productivity and desktop applications to both macOS and Windows users. Reported campaigns associated with CL-CRI-1089 include Operation FlutterBridge, JSCoreRunner (also referred to as FileRipple), Calendaromatic, DocuFlex, AppSuite PDF, RecipeLister, PDFPrime, and ManualzPDF; some reporting also places these campaigns within broader TamperedChef/EvilAI-style activity. The cluster has used malicious Google and YouTube advertisements, sponsored search results, and polished lure websites to distribute malware at scale. Unit 42 reported use of hundreds of verified Google Ads accounts and shell companies for advertising and code-signing support. The cluster primarily leveraged corporate structures connected to Ukrainian entities for code signing, and reporting also links some infrastructure and signing entities to Ukrainian, Malaysian, and British entities. Researchers attributed 34 unique code-signing certificates or entities to CL-CRI-1089 and estimated certificate costs for this cluster alone exceeded $10,000. On macOS, CL-CRI-1089 was linked to Operation FlutterBridge, which delivered the FlutterShell backdoor via fake but functional applications including PodcastsLounge, PDF-Brain, and PDF-Ninja. FlutterShell was built with the Flutter framework, used a WebView-based JavaScript-to-native bridge, and retrieved malicious logic remotely rather than embedding all functionality in the binary. Reported capabilities included arbitrary command execution, file system access, environment variable exfiltration, system fingerprinting, browser session theft, and Google Chrome hijacking by modifying Secure Preferences and redirecting searches and new tabs to attacker-controlled ad sites. PDF-Brain and PDF-Ninja also routed document contents through attacker-controlled servers via an AI summarization feature. Unit 42 reported that observed FlutterShell samples were signed with valid Apple Developer IDs and passed Apple notarization. Unit 42 also linked CL-CRI-1089 to earlier macOS JSCoreRunner/FileRipple activity through shared publisher infrastructure and similar JavaScript-to-native backdoor primitives. On Windows and cross-platform lure operations, the cluster has been associated with trojanized business tools such as calendar and PDF applications that often function as advertised, delay malicious behavior for weeks or months, and later download second-stage payloads including information stealers, remote access Trojans, browser hijackers, adware, and in some cases proxy malware. Calendaromatic was reported as a self-extracting archive containing a working calendar application bundled with a RAT. Victimology described in the reporting is broad and global rather than sector-specific. For Operation FlutterBridge, targeting emphasized English-speaking countries and Western Europe, including the United States, Canada, Australia, France, and Germany.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇫🇷 France
  • 🇩🇪 Germany

Where they're from

Attributed origin per open-source reporting.

  • UA
MITRE ATT&CK

Tradecraft

27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics43 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583×4
Acquire Infrastructure
T1588
Obtain Capabilities
T1588.002
Tool
TA0001
Initial Access
1 technique
T1189
Drive-by Compromise
TA0002
Execution
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.004×2
Unix Shell
T1204
User Execution
T1204.002
Malicious File
T1574
Hijack Execution Flow
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1112
Modify Registry
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
5 techniques
T1027×2
Obfuscated Files or Information
T1036×2
Masquerading
T1218
System Binary Proxy Execution
T1497
Virtualization/Sandbox Evasion
T1497.003×2
Time Based Checks
T1574
Hijack Execution Flow
TA0112
Defense Impairment
2 techniques
T1112
Modify Registry
T1553
Subvert Trust Controls
T1553.002×4
Code Signing
TA0006
Credential Access
1 technique
T1539
Steal Web Session Cookie
TA0007
Discovery
5 techniques
T1033
System Owner/User Discovery
T1057
Process Discovery
T1082×4
System Information Discovery
T1083×3
File and Directory Discovery
T1497
Virtualization/Sandbox Evasion
T1497.003×2
Time Based Checks
TA0009
Collection
1 technique
T1185×4
Browser Session Hijacking
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1105×2
Ingress Tool Transfer
T1568
Dynamic Resolution
TA0010
Exfiltration
1 technique
T1041×3
Exfiltration Over C2 Channel
ARSENAL

Associated malware families

6 malware families attributed to this actor across reporting.

1 additional family tracked in Mallory.

IOCS

Observables

21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Jun 4, 2026
Hackers Use Malicious Ads to Deliver FlutterShell Backdoor on macOS Systems

Financially motivated activity cluster conducting a malvertising campaign since at least 2023, using Google Ads and fake desktop applications to distribute FlutterShell and target Windows and macOS users.

Read more
the hacker newsNews
Jun 4, 2026
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

A cybercrime cluster behind macOS malvertising campaigns that distribute trojanized desktop applications, adware, and the FlutterShell backdoor. The group is linked to Operation FlutterBridge, JSCoreRunner/FileRipple, and broader TamperedChef/EvilAI activity.

Read more
palo alto networks unit 42 blogNews
Jun 2, 2026
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

Cybercrime cluster active since at least 2023, conducting malvertising campaigns targeting Windows and macOS users. It distributes malware masquerading as legitimate desktop applications via Google-verified shell companies. Associated operations include RecipeLister, Calendaromatic, JSCoreRunner, and Operation FlutterBridge delivering FlutterShell. The malware is used primarily for browser hijacking/adware but also has backdoor capabilities including command execution, file manipulation, and environment variable exfiltration.

Read more
security online infoNews
May 26, 2026
Tampered Chef Malware Hidden in Productivity Apps

Infrastructure cluster involved in distributing trojanized productivity software as part of the TamperedChef-style malware operation, using corporate structures connected to Ukrainian entities for code-signing.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping27

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables21

Domains, IPs, and hashes tied to this actor, refreshed continuously.