VYPR
researchPublished Jul 29, 2026· 1 source

Flying Eagle Android RAT Source Code Surfaces, Infrastructure Linked to 170 Servers

The source code for the Flying Eagle Android RAT is circulating on Telegram, with researchers identifying 170 servers hosting its control panels and associated certificates, targeting users in China.

The source code for the Flying Eagle Android remote access trojan (RAT) framework has been discovered circulating within criminal Telegram channels, signaling a potential increase in its availability and use. Security researchers from Hunt.io, in collaboration with independent researcher NetAskari, have identified infrastructure fingerprints on 170 internet servers that match control panels and certificates associated with this RAT framework.

The Flying Eagle RAT is reportedly distributed via a deceptive application masquerading as a Chinese Public Security service, specifically a fake "公安一网通办" (Public Security One-Stop Service) app. This campaign primarily targets Android users within China, aiming to compromise their devices for malicious purposes.

The capabilities of the Flying Eagle framework are extensive, designed to facilitate various forms of mobile espionage and financial fraud. It supports the capture of payment passwords and keystrokes, enabling attackers to steal sensitive financial credentials. Furthermore, it can record screens, access device cameras, and deploy phishing prompts tailored for financial, adult-content, and government-service applications, increasing the likelihood of successful social engineering attacks.

Hunt.io's analysis of telemetry data from the preceding 30 days revealed infrastructure indicators on 170 servers. It is important to note that this server count does not directly equate to the number of infected phones, active operators, or confirmed command-and-control (C2) systems, but rather indicates the presence of the framework's supporting infrastructure.

The researchers employed several methods to identify these servers, including analyzing AdminPro page titles, HTTPS redirect behavior, and matching response headers. An additional 12 servers were identified through a default certificate commonly packaged with the Flying Eagle framework. The researchers suggest that the total count may be conservative, as they excluded similar servers that did not exhibit the expected redirect behavior.

Chinese authorities have issued warnings to the public, advising anyone who may have installed the fraudulent application to immediately remove it, scan their devices for malware, change passwords for affected accounts, freeze payment channels if any funds have been moved, and report the incident to the police. The National Cybersecurity Notification Center in China had previously warned on June 18 about the distribution of this fake application from a specific domain and IP address, highlighting its potential to steal payment data and remotely control devices.

The Flying Eagle code was reportedly distributed as a 388 MB archive named "中国龙.zip" (Chinese Dragon). This archive contains a comprehensive Docker deployment, including nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate. The builder component allows an operator to customize app names, icons, lure text, and C2 addresses before generating a signed APK from one of two available templates. The builder also employs techniques such as randomizing package and class names and encrypting embedded C2 URLs using AES-128-CBC to evade detection.

While the circulation of the source code and the identification of associated infrastructure are confirmed, researchers have not yet established a direct causal link between the two. The report also mentions the emergence of a separate Android control kit called Night Dragon, distributed by one of the Telegram channels involved in promoting Flying Eagle, though it appears to be an independent build.

Synthesized by Vypr AI