Flying Eagle Android RAT: Leaked Code, 170 Servers and Night Dragon

Summary
Researchers traced a fake Chinese Public Security Bureau app to the Flying Eagle Android RAT, identified 170 related servers, and linked leaked code to criminal channels distributing modified builds and a likely successor, Night Dragon.
Key points
- A malicious APK impersonating a Chinese Provincial Public Security Bureau app was distributed through attacker-controlled domains and used as a lure.
- Flying Eagle combines APK building with device-control capabilities, including credential theft, keylogging, screen capture, camera access, and phishing overlays.
- Researchers identified 170 servers using TLS certificate and login-panel fingerprints; the infrastructure was concentrated in Hong Kong, with servers also found in other countries.
- The leaked source code is being modified and distributed through Telegram channels that also offered operational support and cash-out services.
- A likely successor, Night Dragon, was introduced in June 2026 with remote device access and credential-capture features; one exposed panel showed 29 connected devices, but researchers could not verify whether they were victims or test data.
- The report links a malicious sample to the builder’s code and describes obfuscation, encrypted C2 URLs, and padded APK assets intended to hinder static detection.
Article Details
- Attack Vectors
- An attacker-controlled domain hosted a malicious Android APK disguised as a Chinese Provincial Public Security Bureau service app.
- Flying Eagle operators can generate signed APKs with customized lures, icons, application names, and C2 callback addresses.
- Flying Eagle includes phishing overlays for financial, adult, and government-service applications. Night Dragon offers credential-capture prompts for financial applications and cryptocurrency wallets.
- Flying Eagle samples use Android Accessibility Service capabilities and gesture injection for device control.
- Defensive Notes
- A June 2026 Chinese state media notice warned citizens about fraudulent applications disguised as official government services.
- The researchers hunted for Flying Eagle panels using the AdminPro page title, login-route structure, HTTPS redirect headers, and a TLS certificate packaged with the leaked deployment.
- The reported count of 170 Flying Eagle servers may be conservative because the panel query excluded servers that did not return the expected HTTP 302 response.
- The researchers could not verify whether devices shown in an exposed Night Dragon panel were actual victims or dummy data.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 110gongan[.]com | Attacker-controlled domain that hosted the malicious Public Security Bureau-themed APK. |
| DOMAIN | alcs[.]xyttkx[.]cc | Subject of the default TLS certificate packaged with Flying Eagle deployments. |
| DOMAIN | fusu[.]us[.]ci | Domain on a certificate hosted by an IP named in the public safety notice. |
| DOMAIN | fusu666[.]cc | Hardcoded C2 domain in the malicious APK; it presented a Yxç§æ-branded login panel. |
| DOMAIN | h5[.]xyttkx[.]cc | Subdomain identified by the certificate pivot across servers presenting matching Flying Eagle login pages. |
| DOMAIN | ls[.]j2x8a[.]top | Domain associated with a related login panel and certificates on identified infrastructure. |
| DOMAIN | s[.]orove[.]cn | Feiying panel domain identified on the open-directory server. |
| DOMAIN | txl[.]xyttkx[.]cc | Subdomain identified by the certificate pivot across servers presenting matching Flying Eagle login pages. |
| IPV4 | 108[.]187[.]7[.]66 | Server identified through an associated certificate and hosting a related login panel. |
| IPV4 | 108[.]187[.]7[.]71 | Server identified through an associated certificate and hosting a related login panel. |
| IPV4 | 154[.]44[.]25[.]12 | IP paired with an AnyDesk license key found on the open-directory server; listed as investigation infrastructure. |
| IPV4 | 207[.]56[.]30[.]188 | IP named in the public safety notice; the article says Flying Eagle malware's hardcoded C2 domain resolved to it. |
| IPV4 | 207[.]56[.]30[.]194 | IP named in the public safety notice that hosted certificates for associated domains and an APK Confusion Manager panel. |
| IPV4 | 77[.]105[.]161[.]235 | Open-directory server containing a Windows deployment of the Flying Eagle codebase and related artifacts. |
| IPV4 | 85[.]137[.]253[.]48 | Host from which the open-directory server fetched PHP-CGI exploit code, observed on port 8000. |
| SHA256 | 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f | Hash of the Flying Eagle APK generation script ApkBuilder.php. |
| SHA256 | 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a | Hash of net.emulator.anonymizer.executor.apk bundled with the distributed Flying Eagle archive. |
| SHA256 | 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 | Hash of net.extractor.terminator.channel.apk bundled with the distributed Flying Eagle archive. |
| SHA256 | 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b | Hash of com.sequencer.classifier.processor.apk bundled with the distributed Flying Eagle archive. |
| SHA256 | 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df | Hash of a Flying Eagle APK generated during the researchers' local test. |
| SHA256 | 7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af | Hash of BTMOB.exe hosted in the Flying Eagle-related open directory. |
| SHA256 | 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 | Hash of the password-protected BTMOB v4.5.5.zip archive uploaded by Yx Technology. |
| SHA256 | b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 | Hash of net.cataloger.curator.stager.apk bundled with the distributed Flying Eagle archive. |
| SHA256 | c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd | Hash of autoclicker_pro.apk, delivered through 110gongan[.]com. |
| SHA256 | d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e | Hash of net.listener.transactor.authorizer.apk bundled with the distributed Flying Eagle archive. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationApkBuilder.php randomizes package and class names, encrypts embedded C2 callback URLs, and adds low-entropy padding intended to evade detection.T1036 · MasqueradingThe malicious APK impersonated a Provincial Public Security Bureau service app; the builder can assign legitimate-sounding application names.T1056.001 · KeyloggingThe Flying Eagle code includes a LiveKeysStrok class for keylogging.T1113 · Screen CaptureFlying Eagle includes screen capture, and Night Dragon provides live screen viewing.T1123 · Audio CaptureThe Night Dragon device-control interface provides audio recording.
People
Threat Actors
Malware
BTMOB RAT v4.5.5and should not be confused with the popular code hosting platform. A password-protected copy of BTMOB RAT v4.5.5 was posted on the channel May 22nd, however we were unable to conduct further analysis on itsBTMOB V4.0s.orove[.]cn was also identified as a domain for a Feiying (Flying Eagle) panel, and a sample of BTMOB V4.0 was also found in the directory, further pinpointing the intended actions of the operator.Flying Eaglethe source code for an undocumented Android application builder and device control framework called Flying Eagle (é£é¹°). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170Night DragonA likely successor platform called Night Dragon (å¤é¾) was introduced by SQLRCE0 on June 23, 2026, with version 2 already in developmentSpyNoteAPK and base templates found under /user/apps/ in the archive, are detected by sandboxes as SpyNote Android malware. The files share several core behaviors with modern builds linked to the RAT, notably
Vendors
Antbox Networks Limitedtwo additional servers in HuntSQL: 108.187.7[.]66 and 108.187.7[.]71, both hosted on AS138995 (Antbox Networks Limited), also located in Hong Kong.Cognetcloud Inc.CTG Server LimitedNew Hosting Technologies LLCCode Search results for open directories containing "SECRIT_KEY"The server, hosted on AS44493 (New Hosting Technologies LLC) in Finland, contains 2,383 files across 576 sub-directories totaling 1.4 GB. The directoryZillion Network Inc.for associated login pages in HuntSQL returned just two active servers, both hosted on AS54801 (Zillion Network Inc.) in Hong Kong. This provider appears to be a favorite for mobile malware infrastructure, as the
Products
Alipayof the channel, but step-by-step instructions on using remote access tools to drain funds from Alipay and WeChat bank accounts. The message referred victims as "fish" (é±¼) and offered cash-out channels atAndroidWhile conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channelTelegramimpersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device controlWeChatof the channel, but step-by-step instructions on using remote access tools to drain funds from Alipay and WeChat bank accounts. The message referred victims as "fish" (é±¼) and offered cash-out channels at 20-50%
Tools
AttackCapturevariable (SECRIT_KEY) found within the ZIP archive we reviewed provided an unexpected pivot. Querying Attack Capture's Code Search returned an open directory carrying the same typo at 77.105.161[.]235:8000, captured onGitHub V1.2screenshots of users demonstrating control of infected devices, as well as images of a tool named GitHub V1.2, believed to be a standalone application for building malicious APKs. The APK builder was not availableHuntSQLpivots available on the ls.j2x8a[.]top certificate subject, returning two additional servers in HuntSQL: 108.187.7[.]66 and 108.187.7[.]71, both hosted on AS138995 (Antbox Networks Limited), also located in
Countries
CanadaUnited States and mainland China. Individual server instances were also observed in Finland, Malaysia, Canada, and Japan.ChinaThe malware was hosted via the attacker-controlled domain, 110gongan[.]com. GongAn is Pinyin for "Public Security," and is an abbreviation for Provincial Public Security Bureaus in China.Finlandpresence in the United States and mainland China. Individual server instances were also observed in Finland, Malaysia, Canada, and Japan.Germany154.44.25[.]12 (AS979, Hong Kong), and fetched PHP-CGI exploit code from 85.137.253[.]48:8000 (AS215428, Germany).Hong Kongin addition to several resolving domains. Both servers are hosted on AS54801 (Zillon Network Inc.) in Hong Kong. During our analysis, it was identified that 207.56.30[.]194 hosted Let's Encrypt TLS certificates forJapanand mainland China. Individual server instances were also observed in Finland, Malaysia, Canada, and Japan.Malaysiain the United States and mainland China. Individual server instances were also observed in Finland, Malaysia, Canada, and Japan.United Statesis concentrated across a small number of ASNs, primarily in Hong Kong, with a smaller presence in the United States and mainland China. Individual server instances were also observed in Finland, Malaysia, Canada, and