Jamf Threat Labs reported in November 2024 that a macOS Minesweeper app built with Flutter concealed code that could retrieve and execute AppleScript. The researchers found signs that samples had temporarily passed Apple notarization, but could not establish whether attackers had used them against victims. Jamf’s 2026 Security 360 research describes a broader DPRK-aligned threat picture involving fake recruitment and developer workflows—related in context, but distinct from the Flutter game’s delivery method.
What Jamf found in the Flutter Minesweeper app
In its November 12, 2024 analysis, Jamf Threat Labs examined samples uploaded to VirusTotal. They appeared clean at first glance and presented a functional Minesweeper game. The game was based on an open-source Flutter project modified to run on macOS.
The app contacted mbupdate[.]linkpc[.]net, a defanged domain in Jamf’s reporting, and could retrieve a second-stage payload. In controlled analysis, Jamf found that returned content could be reversed and executed as AppleScript. The report noted osascript strings in the sample and connected the behavior to DPRK actors’ earlier use of native AppleScript payloads.
Why Flutter complicated analysis
Flutter packages an application with its framework and Dart code, rather than presenting all of its logic as readily readable source. Jamf said precompiled Dart snapshot symbols and the bundled Flutter layout made decompilation and operational analysis more difficult. In these samples, the malicious code was placed in a dylib named App alongside Flutter frameworks.
#1 Best Overall
That structure can make a plausible game interface a poor guide to what the app does behind the scenes. Analysts need to inspect the packaged components and behavior, not assume that a functional-looking app is benign.
What notarization did—and did not—establish
Jamf observed signs that the samples had been signed and had temporarily passed Apple’s notarization process. As the report put it, “The domains and techniques in the malware align closely with those used in other DPRK malware and show signs that, at one point in time, the malware was signed and had even temporarily passed Apple’s notarization process.”
Rank #2
Notarization is a software-distribution security check, not a guarantee that an app is harmless indefinitely or that it cannot be abused. Jamf’s finding is specific to the samples and the point in time it analyzed them. The researchers could not confirm whether the Flutter samples had reached victims or were preparation for later delivery.
How the 2024 Flutter technique differs from later DPRK-aligned activity
Jamf Security 360’s 2026 Mac research describes FlexibleFerret and related DPRK-aligned activity involving fake recruitment, Terminal commands, credential harvesting, file exfiltration, command execution, and abuse of developer workflows and installers. That context should not be mistaken for proof that the 2024 Minesweeper samples were part of the same delivery chain.
Recommended Free Tools
| Comparison | 2024 Flutter Minesweeper samples | Activity described by Jamf in 2026 |
|---|---|---|
| Lure | A functional Minesweeper game built from a modified open-source Flutter project. | Fake recruitment and interview-related approaches. |
| Execution path | Launching the macOS app; the app could retrieve content for AppleScript execution. | Terminal commands and developer workflows or installers. |
| Reported payload behavior | Jamf’s controlled analysis found returned content could be reversed and run as AppleScript. | Credential harvesting, file exfiltration, and command execution. |
| Trust or workflow abused | Jamf observed signs of signing and temporary notarization. | User interaction with repositories, commands, or installers in a developer workflow. |
Jamf did not publish a standalone prevalence statistic for these findings in the cited reports. The 2024 analysis establishes a capability and a possible delivery preparation, not the number of infections or confirmed victim cases.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How Mac users and administrators can reduce risk
For individual Mac users
- Treat unsolicited interview assessments, coding tests, and requests to install unfamiliar apps with caution, especially when the process is rushed or comes from an unverified contact.
- Do not paste commands into Terminal or run a third-party installer solely because a recruiter, repository, or setup guide tells you to. Verify the source through an independent, trusted channel.
- Check whether a project or installer is expected for the task and comes from the organization’s official account or distribution channel. A working game or a notarized app is not, by itself, proof of safety.
For Mac administrators
- Jamf recommends enabling Threat Prevention and Advanced Threat Controls for Mac in block mode.
- Set a clear process for reviewing unsolicited assessment repositories, developer tools, and third-party installers before users execute them.
- Warn staff specifically about instructions to paste commands into Terminal, and provide a way to verify interview requests and software with the purported organization.
The practical lesson is to assess the delivery context and requested actions, not just the app’s appearance or apparent platform approval. Jamf’s 2024 report documents a Flutter app capable of retrieving an AppleScript payload; its 2026 reporting describes separate-looking recruitment and developer-workflow tactics that also rely on users being induced to run or install something.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

