Published on July 29, 2026
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Severity
Medium
Detail
Cybersecurity researchers have uncovered widespread activity involving Flying Eagle, an Android Remote Access Trojan (RAT) framework whose leaked source code is now circulating in cybercriminal Telegram channels. Researchers from Hunt.io and NetAskari identified approximately 170 internet-facing command-and-control (C2) servers associated with Flying Eagle, indicating active use by multiple threat actors. The framework primarily targets Android users in China through fake government, banking, and service applications, while its public availability significantly lowers the barrier for cybercriminals to launch Android malware campaigns.
How?
The attack begins when victims are lured into installing a malicious Android application masquerading as a legitimate government or public service app, such as China’s “公安一网通办” (Public Security service). These applications are typically distributed through phishing messages, third-party app stores, or malicious download links rather than the official Google Play Store.
Once installed, Flying Eagle registers the infected device with its C2 server and grants attackers extensive remote control capabilities. The malware can:
- Capture SMS messages, including one-time passwords (OTPs).
- Record audio and access the device camera.
- View the device screen remotely.
- Steal contacts, photos, and stored files.
- Log keystrokes and harvest payment credentials.
- Display phishing overlays targeting banking applications, cryptocurrency wallets, Alipay, WeChat, and other financial services.
- Hide its application icon to reduce user suspicion and maintain persistence.
Researchers also discovered that Flying Eagle’s source code was stolen in early 2026 together with customer databases and is now being redistributed through criminal Telegram channels, allowing multiple threat actors to create customised Android malware variants. A successor platform known as Night Dragon has also emerged with enhanced remote administration capabilities, including black-screen mode to conceal attacker activity.
Impact
Flying Eagle provides attackers with complete remote access to infected Android devices, enabling credential theft, financial fraud, surveillance, and identity theft. By intercepting SMS messages and authentication codes while deploying banking overlays, attackers can bypass multi-factor authentication (MFA) and compromise online banking, cryptocurrency wallets, and digital payment accounts.
The public availability of the leaked source code enables other cybercriminals to rapidly deploy new campaigns, increasing the likelihood of widespread Android malware infections and making attribution more difficult. The emergence of the successor platform Night Dragon further demonstrates the continued evolution of this malware ecosystem.
Recommendation
Organizations should:
- Educate users to install Android applications only from trusted sources such as the Google Play Store.
- Prohibit installation of applications from unknown or third-party sources unless explicitly required.
- Deploy Mobile Threat Defense (MTD) or Mobile Device Management (MDM) solutions to detect malicious Android applications.
- Monitor for Android devices communicating with known malicious C2 infrastructure and investigate unusual outbound network traffic.
- Enforce multi-factor authentication using phishing-resistant methods where possible and avoid relying solely on SMS-based OTPs.
- Regularly update Android devices with the latest security patches and remove unsupported devices from corporate environments.
- Perform threat hunting using the indicators of compromise (IOCs) published by Hunt.io and NetAskari.
Conclusion
Flying Eagle is a sophisticated Android RAT framework that has become significantly more dangerous following the public leak of its source code. With at least 170 active C2 servers identified and multiple threat actors now capable of deploying customised variants, the malware poses a growing risk to Android users through credential theft, financial fraud, and remote device compromise. Organizations should strengthen mobile security controls, restrict untrusted application installations, and continuously monitor for indicators of Android malware activity to reduce exposure.
Source
https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
