The world of cyber threats is ever-evolving, and the latest development involves a remote access trojan (RAT) called Flying Eagle, specifically targeting Android users in China. This story is a fascinating glimpse into the intricate world of cybercrime and the constant cat-and-mouse game between attackers and security researchers.
The Flying Eagle RAT
Flying Eagle is a sophisticated Android RAT framework, and its source code has recently been circulating through criminal Telegram channels. This has allowed security researchers at Hunt.io and NetAskari to trace its control panels and certificates to a significant number of internet servers - a total of 170. This number, however, doesn't directly correlate to the number of infected phones or victims, but it's a worrying sign nonetheless.
What makes this particularly fascinating is the kit's capabilities. It can capture payment passwords and keystrokes, record screens, access cameras, and even launch phishing prompts for financial, adult-content, and government-service applications. It's a comprehensive toolkit for cybercriminals, designed to steal sensitive information and remotely control devices.
Tracing the Infrastructure
The researchers at Hunt.io conducted an extensive search, analyzing telemetry data from the preceding 30 days. They identified servers through unique fingerprints, such as the AdminPro page title, HTTPS redirect behavior, and matching response headers. Additionally, they discovered more servers through a default certificate packaged with Flying Eagle.
However, it's important to note that the total count of 170 servers is likely an underestimate. The researchers excluded servers that exhibited similar behavior but didn't return the expected 302 redirect, indicating that the actual number of compromised servers could be even higher.
Impact and Response
Chinese authorities have advised anyone who may have installed the fraudulent application to take immediate action. They recommend removing the app, scanning the device for any potential malware, changing affected account passwords, and freezing payment channels if funds have been moved. Additionally, they encourage victims to report the incident to the police to aid in further investigations.
The Source Code
The Flying Eagle code was distributed as a 388 MB archive named "中国龙.zip" or "Chinese Dragon." It contains a full Docker deployment with various tools and components, including nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate. This comprehensive package allows attackers to create and control their own malicious Android applications.
The control panel of the builder is where the magic happens. An operator can customize the app's name, icon, lure text, and C2 address, and the builder then generates a signed APK from two templates. It even adds low-entropy JSON padding to make the malicious app resemble legitimate software development kit configuration data, making it harder to detect.
Modified Versions and Cash-Out Services
Researchers have observed two Telegram channels, SQLRCE0 and Yx Technology, distributing modified versions of the Flying Eagle framework. Interestingly, Yx Technology also advertised cash-out services, charging a significant percentage of the transaction value. This suggests a well-organized and financially motivated cybercrime operation.
While the server count and source code circulation are documented, the causal relationship between them remains unclear. It's a complex web of cybercriminal activity, and further investigation is required to fully understand the extent of this threat.
Night Dragon: A Separate Android Control Kit
SQLRCE0, one of the Telegram channels, introduced a separate Android control kit called Night Dragon on June 23, 2026. Researchers found two associated servers and an exposed panel, listing 46 devices as online and 29 as actively connected. However, it's unclear whether these entries represent actual victims or test data.
Hunt.io emphasizes that Night Dragon appears to be an independent build, with a second version in development as of July 12. While SQLRCE0 distributed Flying Eagle and promoted Night Dragon, there is no evidence of shared code between the two kits. It's important to differentiate between these two threats, as they have distinct motivations and capabilities.
Conclusion
The Flying Eagle Android RAT and the circulation of its source code highlight the ever-present threat of cybercrime. As attackers become more sophisticated, security researchers must stay one step ahead. This ongoing battle requires constant vigilance, innovative thinking, and a deep understanding of the latest threats. It's a complex and ever-changing landscape, and staying informed is crucial for both individuals and organizations alike.