< Back to all clusters
[TECHNOLOGY] · China · 4 sources

started · updated

Flying Eagle Android RAT Powers 170 Servers in Global Cybercrime Network

A leaked Android remote‑access trojan known as Flying Eagle is being exploited by a large criminal ecosystem. Researchers traced the framework to 170 active servers and identified two Telegram channels that distribute modified versions of the stolen code. The malware is packaged as fake applications, notably an impersonated Chinese Provincial Public Security Bureau service, to lure victims into installing malicious APKs. The source code was stolen in early 2026 along with nearly 200 customer databases, after which it was offered for sale (around 2,000 USDT) or released for free via Docker containers. A successor platform, dubbed Night Dragon, is already appearing in the wild, indicating the threat’s continued evolution.

The builder allows operators to customize app names, icons, and command‑and‑control addresses, then generate signed APKs that can capture screens, log keystrokes, access cameras, and overlay fake login pages. Security firm Hunt.io disclosed the findings, highlighting the risk of financial fraud and other malicious activities facilitated by this readily available Android RAT.

Entities

Chinese Public Security Bureau · Flying Eagle · Hunt.io · Night Dragon