The source code for the Flying Eagle Android remote access trojan (RAT) framework has been observed circulating within criminal Telegram channels. This distribution includes a comprehensive Docker deployment package, named 中国龙.zip (Chinese Dragon), which contains all necessary components for operation, such as nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate.
Hunt.io and independent researcher NetAskari have traced control panels and certificates associated with the Flying Eagle RAT to 170 internet servers. This identification was primarily achieved by searching for specific infrastructure fingerprints, including the "AdminPro" page title, HTTPS redirect behavior, and matching response headers. An additional 12 servers were found through a default certificate packaged with the RAT.
The Flying Eagle framework has been linked to a fraudulent "公安一网通办" (Public Security service) application designed to target Android users in China. The RAT possesses various malicious capabilities, including the capture of payment passwords and keystrokes, screen recording, camera access, and the display of phishing prompts for financial, adult-content, and government-service applications. Chinese authorities have issued warnings and advice for users who may have installed the fake application.
The Flying Eagle builder allows operators to customize an application's name, icon, lure text, and command-and-control (C2) address, then generates a signed APK from one of two templates. The builder randomizes package and class names, encrypts embedded C2 URLs using AES-128-CBC, and adds JSON padding to evade detection. Samples analyzed from the builder have been detected as SpyNote and utilize Android accessibility services for privilege escalation and gesture injection.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The source code for the Flying Eagle Android remote access trojan (RAT) is being distributed via criminal Telegram channels, with researchers identifying 170 internet servers hosting its control panels. This RAT framework is linked to a fake Chinese public security application and can capture payment passwords, record screens, and access cameras, posing a significant threat to Android users.