A recently leaked Android Remote Access Trojan (RAT) known as ‘Flying Eagle’ has been identified as the driving force behind a vast and expanding network of cybercriminal activity. This sophisticated toolkit enables operators to craft counterfeit Android applications, seize control of compromised devices, and extract sensitive information, potentially leading to significant financial fraud.
The distribution strategy for Flying Eagle involves disguising malicious apps as legitimate Chinese Public Security Bureau services. This tactic leverages the inherent trust and urgency associated with official government applications, increasing the likelihood that users will overlook potential red flags during the installation process.
Discovery and Analysis
Cybersecurity researchers at Hunt.io uncovered the widespread use of Flying Eagle after tracing a malicious APK back to attacker-controlled domains and Telegram channels disseminating the RAT’s source code. Their investigation revealed a leaked builder and device-control framework that had already been adapted by multiple criminal entities.
The scale of this operation is substantial. Analysts identified 170 servers linked to Flying Eagle’s infrastructure. Concurrently, a related Telegram channel introduced ‘Night Dragon,’ a new Android RAT poised for broader deployment.
Capabilities and Distribution
Flying Eagle is more than just a malicious application; it is a comprehensive framework that allows operators to create customized Android packages and manage compromised devices via a web-based control panel. The builder can modify app names, icons, package identifiers, and command-and-control addresses before generating a signed APK.
The malware’s templates mimic a variety of applications, including financial services, adult streaming platforms, social media networks, and public service portals. This versatility mirrors tactics observed in previous fraudulent emergency alert app campaigns, where trusted themes are exploited to persuade users into installing harmful software.
Once installed, Flying Eagle can exploit Android’s Accessibility Services to capture screen content, log keystrokes, access the device’s camera, and overlay fake login pages atop legitimate applications. Such permission abuses have been noted in prior Android banking overlay threats, underscoring the importance of scrutinizing access requests during app installations.
Infrastructure and Evolution
The source code for Flying Eagle was reportedly stolen in early 2026, along with nearly 200 customer databases. Subsequently, two Telegram channels, SQLRCE0 and Yx Technology, distributed patched versions, provided technical support, and offered tools to assist operators in deploying and monetizing infections.
Hunt.io’s analysis identified 158 servers utilizing Flying Eagle’s infrastructure, with an additional 12 systems employing the framework’s default TLS certificate. The majority of these servers are hosted in Hong Kong, with others located in the United States, mainland China, Finland, Malaysia, Canada, and Japan. This geographical dispersion complicates efforts to mitigate the threat through simple domain blocking, especially given the operators’ practice of regularly rotating certificates and hosting locations.
Emergence of ‘Night Dragon’
On June 23, 2026, SQLRCE0 introduced ‘Night Dragon,’ a separately developed Android remote-control toolkit. This new RAT boasts capabilities such as capturing passwords from banking and payment applications, concealing its icon post-installation, and displaying a fake system-update screen to mask malicious activities.
During the investigation, researchers identified two active Night Dragon servers. Although the platform is still in its early stages, with version 2 already in development, one exposed management panel showed 46 devices online and 29 actively connected. However, it remains unclear whether these records represent actual victims or test data.
The control panel offers extensive access to compromised devices, including live screen viewing, text messages, photos, audio recordings, camera feeds, and files. Additionally, it can deploy phishing overlays targeting payment services, banks, and cryptocurrency wallets, posing a significant risk to users who conduct financial transactions on their mobile devices.
The rapid proliferation of sophisticated Android RATs like Flying Eagle and Night Dragon highlights the evolving landscape of mobile cyber threats. Users are advised to exercise caution when installing applications, especially those requesting extensive permissions or originating from unofficial sources. Regularly updating devices and employing robust security measures can help mitigate the risks associated with such advanced malware campaigns.