The real break is the delivery layer. CL-CRI-1089 can keep macOS malware in circulation because the ads themselves look legitimate to the platform, so takedowns of single lures do not end the campaign.
Unit 42 says Operation FlutterBridge has moved from JSCoreRunner/FileRipple to FlutterShell, a Flutter-built backdoor with adware functions. The campaign is using Google-verified shell companies and malicious Google and YouTube ads to push fake desktop apps, and the samples were signed with valid Apple Developer IDs and passed notarization, which blunts normal trust checks on both the ad and app sides.
That combination extends the exposure window. A campaign that can reissue ads through verified entities and ship notarized macOS apps can outlast routine blocklists and keep reaching users even after individual artifacts are removed.
The targets remain macOS users in the U.S., Canada, Australia, France, and Germany, and the payload still supports command execution, file system interaction, and environment-variable exfiltration. The important change is that the operator now has a more durable, scalable way to deliver the same malware through channels users and defenders are trained to trust.