Researchers at Hunt.io have uncovered a sprawling criminal ecosystem utilizing the leaked Flying Eagle Android RAT framework to deploy fraudulent apps and target Chinese mobile users.
Key Points
- Hunt.io identified 170 active servers running the Flying Eagle framework, which enables remote device control and credential theft.
- The malware source code was leaked in early 2026, allowing criminal actors to distribute modified versions via Telegram channels like Yx科技 and SQLRCE0.
- Flying Eagle features include phishing overlays for major Chinese financial institutions, cryptocurrency wallets, and government services to capture sensitive user data.
- Operators use advanced evasion techniques, including randomized class naming and AES-128-CBC encryption, to bypass antivirus detection and static analysis.
- A successor platform named Night Dragon is currently in active development, featuring enhanced capabilities like fake system update screens and automatic icon hiding.