[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxaUeWi_37abSoeEVGfOvvqrnZ73WDaS9enCImQvJILs":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"aba86172-ca92-46a7-9158-a8b0967f3c54","Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates","flying-eagle-android-rat-traces-found-on-170-servers-as-source-code-circulates-940657","Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake \"公安一网通办\" Public Security service application targeting Android users in China. The kit supports payment-password","Source code for the Flying Eagle Android remote access trojan (RAT) is being distributed through criminal Telegram channels. Researchers Hunt.io and NetAskari traced 170 servers hosting matching control panels and certificates, linking the framework to a fake Chinese Public Security application. The kit enables payment-password theft, keystroke capture, screen recording, camera access, and phishing attacks targeting Android users in China.","Flying Eagle Android RAT source code circulates; 170 servers traced with control panels.","Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates Swati KhandelwalJul 29, 2026Mobile Security \u002F Threat Intelligence Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake \"公安一网通办\" Public Security service application targeting Android users in China. The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts for financial, adult-content, and government-service applications. Hunt.io's search of the preceding 30 days of telemetry found infrastructure fingerprints on 170 servers, a count that does not establish 170 infected phones, victims, operators, or confirmed command-and-control (C2) systems. The researchers found 158 servers through the AdminPro page title, HTTPS redirect behaviour, and matching response headers, then identified 12 more through a default certificate packaged with Flying Eagle. They said the total is likely conservative because it excluded otherwise similar servers that did not return the expected 302 redirect. Chinese authorities advised anyone who installed the fraudulent application to remove it, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to police. China's National Cybersecurity Notification Center warned on June 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal payment data and remotely control devices. According to joint research published July 28, the Flying Eagle code was distributed as a 388 MB archive called 中国龙.zip, or Chinese Dragon. It contains a full Docker deployment with nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate. The panel lets an operator choose an app name, icon, lure text, and C2 address, then produces a signed APK from one of two templates. The builder randomises package and class names, encrypts embedded C2 URLs using AES-128-CBC, and adds 2.8 MB to 3.5 MB of low-entropy JSON padding designed to resemble legitimate software development kit configuration data. Flying Eagle is the builder and control framework; Hunt.io said samples it analysed from the builder were detected as SpyNote and used Android accessibility services for privilege escalation and gesture injection. The researchers observed two Telegram channels, SQLRCE0 and Yx Technology, distributing modified versions of the framework. Messages reviewed by them claimed an unidentified party had compromised customer infrastructure containing 189 Flying Eagle servers and exfiltrated database data, but neither claim has been independently confirmed. Yx Technology also advertised cash-out services charging 20% to 50% of the transaction value. The server count and the source-code circulation are documented, but no causal relationship between them has been established. SQLRCE0 introduced a separate Android control kit called Night Dragon on June 23, 2026. The researchers found two associated servers and an exposed panel that listed 46 devices as online and 29 as actively connected, but said it could not determine whether the entries represented victims or test data. Hunt.io says Night Dragon appears to be an independent build, with a second version in development as of July 12. The report establishes that SQLRCE0 distributed Flying Eagle and promoted Night Dragon, but it does not establish shared code. This is not the 2011 China-linked espionage campaign McAfee named Night Dragon. The 2026 kit is financially motivated Android crimeware. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android, Credential Theft, Cybercrime, Financial Fraud, Malware, mobile security, Phishing, Remote Access Trojan, Spyware, Threat Intelligence ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fflying-eagle-android-rat-traces-found.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhOpdosdOAoAjpR73DY5i_8YN9dHOY7KsBws53ivjlY3iVg0-EZAO6CliWbdg61_hT6eI9_Im9aiH_c312ttIHamIl4IIxe2omPSWjC4OaCfbNKZC7Gr85jXs12NObtpiSAK1PNljccRdmzvITRijNNh16c2IDK3kWmL5Ce3lbzQNCJaMy4wgKwWyB2oiI\u002Fs1600\u002Fandroid-rat.jpg","2026-07-29T07:07:23+00:00","2026-07-29T08:00:33.898578+00:00",9,[18,21,23,26],{"name":19,"type":20},"SQLRCE0","threat_actor",{"name":22,"type":20},"Yx Technology",{"name":24,"type":25},"Android","technology",{"name":27,"type":28},"Flying Eagle","campaign","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":29,"icon":31,"name":32,"slug":33},null,"Malware","malware",[35],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41,45,49,51,54],{"type":42,"value":43,"context":44},"domain","110gongan.com","Distribution point for fake Public Security application hosting Flying Eagle RAT",{"type":46,"value":47,"context":48},"ip","207.56.30.188","Associated with 110gongan.com malicious application distribution",{"type":33,"value":27,"context":50},"Android RAT framework with builder and C2 control panel; 170 servers identified",{"type":33,"value":52,"context":53},"Night Dragon","Separate Android control kit promoted by SQLRCE0 Telegram channel; 2 servers found",{"type":33,"value":55,"context":56},"SpyNote","Detection name for Flying Eagle samples analyzed; uses Android accessibility services"]