← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Flying Eagle Android RAT Source Code Circulates, 170 Servers Identified

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Flying Eagle Android RAT source code is circulating in criminal Telegram channels.
  • Hunt.io and NetAskari found 170 servers with matching control panels and certificates.
  • The RAT is linked to a fake "公安一网通办" app targeting Android users in China.
  • Capabilities include payment-password capture, screen recording, and camera access.

Flying Eagle RAT Source Code Distribution

The source code for the Flying Eagle Android remote access trojan (RAT) framework has been observed circulating within criminal Telegram channels. This distribution includes a comprehensive Docker deployment package, named 中国龙.zip (Chinese Dragon), which contains all necessary components for operation, such as nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate.

Infrastructure Identification

Hunt.io and independent researcher NetAskari have traced control panels and certificates associated with the Flying Eagle RAT to 170 internet servers. This identification was primarily achieved by searching for specific infrastructure fingerprints, including the "AdminPro" page title, HTTPS redirect behavior, and matching response headers. An additional 12 servers were found through a default certificate packaged with the RAT.

Targeting and Capabilities

The Flying Eagle framework has been linked to a fraudulent "公安一网通办" (Public Security service) application designed to target Android users in China. The RAT possesses various malicious capabilities, including the capture of payment passwords and keystrokes, screen recording, camera access, and the display of phishing prompts for financial, adult-content, and government-service applications. Chinese authorities have issued warnings and advice for users who may have installed the fake application.

Builder Functionality and Detection

The Flying Eagle builder allows operators to customize an application's name, icon, lure text, and command-and-control (C2) address, then generates a signed APK from one of two templates. The builder randomizes package and class names, encrypts embedded C2 URLs using AES-128-CBC, and adds JSON padding to evade detection. Samples analyzed from the builder have been detected as SpyNote and utilize Android accessibility services for privilege escalation and gesture injection.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The source code for the Flying Eagle Android remote access trojan (RAT) is being distributed via criminal Telegram channels, with researchers identifying 170 internet servers hosting its control panels. This RAT framework is linked to a fake Chinese public security application and can capture payment passwords, record screens, and access cameras, posing a significant threat to Android users.