top of page
perceptive_background_267k.jpg

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Published:

29 July 2026 at 09:07:23

Alert date:

29 July 2026 at 10:02:49

Source:

thehackernews.com

Click to open the original link from this advisory

Mobile & IoT, Ransomware & Malware, Data Breach & Exfiltration

The source code for the Flying Eagle Android remote access trojan (RAT) framework is being distributed through criminal Telegram channels. Researchers from Hunt.io and independent researcher NetAskari identified matching control panels and SSL certificates across 170 internet-facing servers. The framework has been linked to a fraudulent application impersonating the Chinese public security service '公安一网通办'. The RAT targets Android users in China and supports theft of payment passwords and other sensitive data. The widespread circulation of the source code raises concerns about increased adoption by threat actors and potential expansion of campaigns.

Technical details

Flying Eagle is an Android RAT (Remote Access Trojan) builder and control framework whose source code is circulating on criminal Telegram channels. The code was distributed as a 388 MB archive named '中国龙.zip' (Chinese Dragon). It contains a full Docker deployment stack including nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default TLS certificate. The panel allows operators to customize app name, icon, lure text, and C2 address, then generates a signed APK from one of two templates. The builder randomizes package and class names, encrypts embedded C2 URLs using AES-128-CBC, and adds 2.8–3.5 MB of low-entropy JSON padding designed to mimic legitimate SDK configuration data. Samples analyzed were detected as SpyNote and used Android accessibility services for privilege escalation and gesture injection. Capabilities include payment-password and keystroke capture, screen recording, camera access, and phishing prompts targeting financial, adult-content, and government-service applications. Hunt.io identified 158 servers via AdminPro page title, HTTPS redirect behavior, and matching response headers, and 12 more via a default certificate bundled with Flying Eagle, totaling 170 servers. The framework was used to distribute a fake '公安一网通办' (Public Security) app targeting Android users in China. A related but independent Android control kit called Night Dragon was introduced by Telegram channel SQLRCE0 on June 23, 2026, with two associated servers found and an exposed panel listing 46 devices as online and 29 actively connected. Night Dragon appears to be a second version in development as of July 12, 2026, and is financially motivated crimeware unrelated to the 2011 McAfee Night Dragon espionage campaign.

Mitigation steps:

1. Remove any installed instance of the fraudulent '公安一网通办' application immediately. 2. Perform a full malware scan on affected Android devices. 3. Change all account passwords that may have been exposed, particularly for financial and government-service accounts. 4. Freeze payment channels if any unauthorized fund movement is detected. 5. Report incidents to local police authorities. 6. Block the known IOCs: domain 110gongan[.]com and IP 207.56.30[.]188 at network perimeter. 7. Hunt for Flying Eagle C2 infrastructure using the AdminPro page title, matching HTTPS 302 redirect behavior, and default TLS certificate fingerprints across internet-facing telemetry. 8. Monitor for APKs with randomized package/class names, AES-128-CBC encrypted C2 URLs, and anomalous JSON padding in the 2.8–3.5 MB range. 9. Monitor Telegram channels SQLRCE0 and Yx Technology for further distribution of Flying Eagle or Night Dragon variants. 10. Detect SpyNote indicators on Android endpoints, as Flying Eagle-built samples are detected under this signature. 11. Disable or restrict Android Accessibility Services for untrusted applications to limit privilege escalation and gesture injection.

Affected products:

Android devices (targeted via fake '公安一网通办' Public Security service application)
Flying Eagle Android RAT framework (builder and C2 panel)
SpyNote (underlying malware detected in Flying Eagle-built samples)
Night Dragon Android control kit (related independent crimeware)

Related links:

Related CVE's:

Related threat actors:

IOC's:

110gongan[.]com (distribution domain for fake Public Security app), 207.56.30[.]188 (IP associated with 110gongan[.]com), 中国龙.zip / Chinese Dragon (388 MB archive containing Flying Eagle source code), AdminPro panel page title (HTTP fingerprint for Flying Eagle C2 servers), Default TLS/HTTPS certificate bundled with Flying Eagle framework, 302 redirect behavior on Flying Eagle C2 servers, AES-128-CBC encrypted C2 URLs embedded in APKs, 2.8–3.5 MB low-entropy JSON padding in APK files, SQLRCE0 (Telegram channel), Yx Technology (Telegram channel)

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page