Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates



A recent report has exposed the Flying Eagle Android RAT framework, which is being circulated through malicious channels, exposing 170 servers hosting the malicious application. Android users are advised to exercise extreme caution when interacting with unfamiliar apps and to maintain stringent cybersecurity measures.

  • The Flying Eagle Android Remote Access Trojan (RAT) framework has gained notoriety due to its extensive presence on 170 internet servers traced back to criminal Telegram channels.
  • The source code for the Flying Eagle RAT framework is being circulated through these malicious channels, allowing cybercriminals to exploit unsuspecting Android users.
  • The framework boasts an array of capabilities, including payment-password and keystroke capture, screen recording, camera access, and phishing prompts tailored to specific applications such as financial services, adult content, and government services.
  • Chinese authorities have issued warnings advising Android users who installed the fraudulent application to remove it, scan their devices, change affected account passwords, freeze payment channels if funds moved, and report the incident to the police.
  • The Flying Eagle code is being distributed as a 388 MB archive called "中国龙.zip," or "Chinese Dragon," which contains phishing templates, an Android build tool, and other tools for creating signed APKs.
  • A second component of this campaign is the Night Dragon Android control kit, introduced on June 23, 2026, which appears to be financially motivated Android crimeware.



  • The cybersecurity landscape has been marred by an increasing number of sophisticated cyber threats, and a recent report by Hunt.io and independent researcher NetAskari sheds light on the rapidly evolving threat landscape. The Flying Eagle Android Remote Access Trojan (RAT) framework has gained notoriety due to its extensive presence on 170 internet servers that have been traced back to criminal Telegram channels.

    According to the report, the source code for the Flying Eagle Android RAT framework is being circulated through these malicious channels, allowing cybercriminals to exploit unsuspecting Android users. The framework boasts an array of capabilities, including payment-password and keystroke capture, screen recording, camera access, and phishing prompts tailored to specific applications such as financial services, adult content, and government services.

    Hunt.io and NetAskari undertook a comprehensive investigation that revealed the presence of 158 servers via the AdminPro page title, HTTPS redirect behaviour, and matching response headers. The researchers were able to identify an additional 12 servers through a default certificate packaged with Flying Eagle. It is worth noting that this total count may not be exhaustive, as it did not include otherwise similar servers that failed to return the expected 302 redirect.

    In light of these findings, Chinese authorities have issued warnings advising Android users who installed the fraudulent application to remove it, scan their devices, change affected account passwords, freeze payment channels if funds moved, and report the incident to the police. China's National Cybersecurity Notification Center had previously warned on June 18 that the fake application was being distributed from 110gongan[.]com, associated with IP address 207.56.30[.]188, which could potentially steal sensitive payment data and remotely control devices.

    Further analysis by Hunt.io revealed that the Flying Eagle code is being distributed as a 388 MB archive called "中国龙.zip," or "Chinese Dragon." This package contains a full Docker deployment with nginx, PHP, MySQL, an Android build tool, phishing templates, and a default Transport Layer Security certificate. Notably, this setup allows an operator to select an app name, icon, lure text, and C2 address before producing a signed APK from one of two templates.

    Hunt.io discovered that samples it analyzed from the builder were detected as SpyNote and utilized Android accessibility services for privilege escalation and gesture injection. The researchers observed two Telegram channels, SQLRCE0 and Yx Technology, distributing modified versions of the framework. The messages reviewed by them claimed an unidentified party had compromised customer infrastructure containing 189 Flying Eagle servers and exfiltrated database data; however, neither claim has been independently confirmed.

    A second component of this campaign is the Night Dragon Android control kit, which was introduced on June 23, 2026. Hunt.io found two associated servers and an exposed panel that listed 46 devices as online and 29 as actively connected. However, it could not determine whether these entries represented genuine victims or test data. According to the researchers, Night Dragon appears to be an independent build with a second version in development as of July 12.

    SQLRCE0 distributed Flying Eagle and promoted Night Dragon but did not establish any shared code between them. This is distinct from the 2011 China-linked espionage campaign named Night Dragon by McAfee. The present kit appears to be financially motivated Android crimeware.

    The server count and source-code circulation are documented, although no causal relationship between these has been established. Hunt.io's search of the preceding 30 days of telemetry revealed infrastructure fingerprints on 170 servers, a count that does not necessarily establish 170 infected phones, victims, operators, or confirmed command-and-control (C2) systems.

    In light of this latest development, it is imperative for Android users to exercise extreme caution when interacting with unfamiliar applications and maintain stringent cybersecurity measures. The emergence of such sophisticated cyber threats underscores the need for robust security protocols and awareness campaigns to safeguard individual privacy and protect against financial loss.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Flying-Eagle-Android-RAT-Traces-Found-on-170-Servers-as-Source-Code-Circulates-ehn.shtml

  • https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html

  • https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

  • https://cyberpress.org/flying-eagle-breeds-night-dragon/


  • Published: Wed Jul 29 03:26:10 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us