AUTO-UPDATED

Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App

Researchers at Hunt.io have uncovered a sprawling criminal ecosystem utilizing the leaked Flying Eagle Android RAT framework to deploy fraudulent apps and target Chinese mobile users.

Key Points

  • Hunt.io identified 170 active servers running the Flying Eagle framework, which enables remote device control and credential theft.
  • The malware source code was leaked in early 2026, allowing criminal actors to distribute modified versions via Telegram channels like Yx科技 and SQLRCE0.
  • Flying Eagle features include phishing overlays for major Chinese financial institutions, cryptocurrency wallets, and government services to capture sensitive user data.
  • Operators use advanced evasion techniques, including randomized class naming and AES-128-CBC encryption, to bypass antivirus detection and static analysis.
  • A successor platform named Night Dragon is currently in active development, featuring enhanced capabilities like fake system update screens and automatic icon hiding.

Why it Matters

The proliferation of this leaked framework demonstrates how easily sophisticated malware can be commoditized and distributed within underground criminal markets. This evolution forces security professionals to contend with a rapidly shifting landscape where exposed tools are quickly replaced by more advanced, independently developed successors.
Securityaffairs.com Published by Pierluigi Paganini
Read original