VMTech
+381 11 4183 54024/7 Discuss a project

Flying Eagle source code circulates as researchers map 170 servers

Flying Eagle source code circulates as researchers map 170 servers

Joint research published July 28, 2026, found Flying Eagle Android RAT fingerprints on 170 internet servers as the framework’s source code circulated through criminal Telegram channels. Hunt.io and researcher NetAskari stressed that the figure does not represent 170 victims, infected phones, operators or confirmed C2 systems.

Why the framework matters

Flying Eagle was linked to a fraudulent Chinese Public Security service application targeting Android users in China. Its functions include payment-password and keystroke capture, screen recording, camera access, device control and phishing prompts that imitate financial, adult-content and government-service apps.

The framework lowers the barrier to deploying customised malware. An operator can select a name, icon, lure and C2 address, then generate a signed APK from one of two templates.

How researchers identified the infrastructure

Hunt.io found 158 servers through the AdminPro page title, HTTPS redirect behaviour and matching response headers. Another 12 used the default TLS certificate packaged with Flying Eagle. The estimate is likely conservative because similar servers without the expected 302 redirect were excluded.

The leaked 388 MB archive, named Chinese Dragon, contains a Docker deployment with nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools and phishing templates. The builder randomises package and class names, encrypts embedded C2 addresses with AES-128-CBC and adds 2.8 MB to 3.5 MB of low-entropy JSON padding.

Related criminal activity

Builder-generated samples were detected as SpyNote and abused Android accessibility services for privilege escalation and gesture injection. Two channels, SQLRCE0 and Yx Technology, distributed modified versions. Claims that 189 customer servers were compromised remain unverified. SQLRCE0 also promoted Night Dragon, an apparently independent Android kit; one exposed panel listed 46 online devices and 29 active connections, though these may have been test records.

For businesses, the response should focus on controlling APK installation, monitoring accessibility-service use and preparing rapid containment. If an unofficial app reaches a device, remove it, scan the handset, reset affected credentials and freeze payment channels immediately when funds may be at risk.

#androidsecurity#malware#threatintel#cybercrime
Open analytics
On the site 2 views
min read 3 29.07.2026
Instagram

Flying Eagle source code circulates as researchers map 170 servers

Open the post on Instagram ↗