Threats Tagged 'jscorerunner'
View all threats tagged with 'jscorerunner'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'jscorerunner'
Click on any threat for detailed analysis and mitigation recommendations
A financially-motivated cybercrime cluster designated CL-CRI-1089 has launched Operation FlutterBridge, deploying FlutterShell backdoor malware targeting macOS systems through malvertising. Built with the Flutter framework, FlutterShell masquerades as legitimate applications including podcast players and PDF viewers, delivering adware with full backdoor capabilities such as shell command execution and file system manipulation. The malware uses a WebView-based architecture with JavaScript-to-native bridge, allowing attackers to dynamically modify behavior without recompiling. Distribution occurs through hundreds of Google-verified advertisements controlled by shell companies including AdsParkPro LTD and Advantage Web Marketing LLC. The campaign primarily targets Anglophone and Western European markets. All samples were signed with valid Apple Developer IDs and successfully passed notarization, achieving zero detections on VirusTotal initially. The malware hijacks Google Chrome browsers, redirecting traffic ... Join the discussion | AlienVault OTX General | 06/02/2026, 14:33:49 UTC Added: 06/03/2026, 09:33:37 UTC |
Mosyle has discovered a new Mac malware strain called 'JSCoreRunner' that evades detection by masquerading as a PDF conversion tool. The malware spreads through a malicious website, fileripple.com, and operates in two stages. The first stage, FileRipple.pkg, appears as a legitimate PDF tool while running malicious code in the background. The second stage, Safari14.1.2MojaveAuto.pkg, bypasses Gatekeeper's protections. Once installed, JSCoreRunner targets Chrome browsers, altering search engine settings to redirect users to fraudulent providers. This exposes users to keylogging, phishing, and potential data theft. The malware's sophisticated approach highlights the need for vigilance and proactive security measures for Mac administrators. Join the discussion | AlienVault OTX General | 08/29/2025, 20:19:59 UTC Added: 09/01/2025, 08:47:39 UTC |
Showing 1 to 2 of 2 results