Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Flying Eagle Android RAT: A Growing Cybercrime Ecosystem Behind Fake Chinese Police Apps


Researchers have exposed a sophisticated network of servers and tools behind fake Chinese police apps that use a leaked Android RAT framework called Flying Eagle. The discovery highlights the growing threat of cybercrime and emphasizes the need for vigilance in protecting against malware attacks.

  • The team at Hunt.io uncovered a sophisticated network of servers and tools related to the leaked Android RAT framework called Flying Eagle (also known as 飞鹰).
  • The leaked codebase contains malicious tools, including an APK generator, device control features, and encryption techniques.
  • Two Telegram channels, Yx科技 and SQLRCE0, are operating around the Flying Eagle framework, offering cash-out services and independently developed successor tooling called Night Dragon.
  • The emergence of Night Dragon suggests that demand for Chinese-language Android RAT tooling continues to drive criminal actors.
  • The discovery has significant implications for individuals and organizations, including data breaches, phishing campaigns, and unauthorized access to sensitive information.



  • The world of cybercrime has witnessed numerous exploits and vulnerabilities in recent years, but one particularly alarming development has emerged from a team of researchers at Hunt.io. In a groundbreaking expose, the researchers have uncovered a sophisticated network of servers, channels, and tools that appear to be part of a larger criminal ecosystem centered around a leaked Android RAT framework called Flying Eagle (also known as 飞鹰). This malicious framework has been used to create fake police apps that impersonate Chinese Provincial Public Security Bureau services.

    According to the researchers, the leak of the Flying Eagle source code in early 2026 led to the creation of multiple modified variants of the framework, which have been distributed across various channels and platforms. The leaked codebase contains a range of malicious tools, including an APK generator, device control features, phishing overlays for financial, adult, and government service apps, and encryption techniques that make it difficult for antivirus software to detect.

    The researchers discovered that two Telegram channels, Yx科技 and SQLRCE0, have been operating around the Flying Eagle framework. Yx科技 serves as a sales and operational support platform, offering cash-out services at 20-50 percent transaction fees. On the other hand, SQLRCE0 has introduced Night Dragon, an independently developed successor to Flying Eagle that adds features such as automatic icon hiding after installation, single-click credential capture overlays for major Chinese banks, and live screen viewing capabilities.

    Despite the initial discovery of the fake police apps in June 2026, it was not until three weeks later that a public safety notice was issued by Chinese state media. However, the emergence of Night Dragon only a few days after this warning suggests that the demand for Chinese-language Android RAT tooling continues to drive criminal actors.

    Hunt.io's researchers used various methods, including analyzing TLS certificates and panel fingerprints, to identify 170 servers running the Flying Eagle framework. They also found that SQLRCE0 had made multiple fixes to the leaked source code, including domain connectivity, WebSocket stability, anti-uninstall features, and more, all while assuring users with a money-back guarantee that all backdoors had been removed from the code.

    The discovery of this complex cybercrime ecosystem has significant implications for individuals and organizations. The use of fake police apps and Android RAT frameworks can lead to various forms of malware attacks, including data breaches, phishing campaigns, and unauthorized access to sensitive information.

    In conclusion, the Flying Eagle Android RAT framework represents a growing threat in the world of cybercrime. As researchers continue to uncover new vulnerabilities and exploits, it is essential for individuals and organizations to remain vigilant and take proactive measures to protect themselves from such attacks.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Flying-Eagle-Android-RAT-A-Growing-Cybercrime-Ecosystem-Behind-Fake-Chinese-Police-Apps-ehn.shtml

  • https://securityaffairs.com/196369/malware/researchers-expose-flying-eagle-criminal-ecosystem-behind-fake-chinese-police-app.html


  • Published: Thu Jul 30 19:10:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us