Flying Eagle Android RAT: Leaked Code, 170 Servers and Night Dragon

· Original article ↗

Summary

Researchers traced a fake Chinese Public Security Bureau app to the Flying Eagle Android RAT, identified 170 related servers, and linked leaked code to criminal channels distributing modified builds and a likely successor, Night Dragon.

Key points

  • A malicious APK impersonating a Chinese Provincial Public Security Bureau app was distributed through attacker-controlled domains and used as a lure.
  • Flying Eagle combines APK building with device-control capabilities, including credential theft, keylogging, screen capture, camera access, and phishing overlays.
  • Researchers identified 170 servers using TLS certificate and login-panel fingerprints; the infrastructure was concentrated in Hong Kong, with servers also found in other countries.
  • The leaked source code is being modified and distributed through Telegram channels that also offered operational support and cash-out services.
  • A likely successor, Night Dragon, was introduced in June 2026 with remote device access and credential-capture features; one exposed panel showed 29 connected devices, but researchers could not verify whether they were victims or test data.
  • The report links a malicious sample to the builder’s code and describes obfuscation, encrypted C2 URLs, and padded APK assets intended to hinder static detection.

Article Details

Attack Vectors
  • An attacker-controlled domain hosted a malicious Android APK disguised as a Chinese Provincial Public Security Bureau service app.
  • Flying Eagle operators can generate signed APKs with customized lures, icons, application names, and C2 callback addresses.
  • Flying Eagle includes phishing overlays for financial, adult, and government-service applications. Night Dragon offers credential-capture prompts for financial applications and cryptocurrency wallets.
  • Flying Eagle samples use Android Accessibility Service capabilities and gesture injection for device control.
Defensive Notes
  • A June 2026 Chinese state media notice warned citizens about fraudulent applications disguised as official government services.
  • The researchers hunted for Flying Eagle panels using the AdminPro page title, login-route structure, HTTPS redirect headers, and a TLS certificate packaged with the leaked deployment.
  • The reported count of 170 Flying Eagle servers may be conservative because the panel query excluded servers that did not return the expected HTTP 302 response.
  • The researchers could not verify whether devices shown in an exposed Night Dragon panel were actual victims or dummy data.

Indicators of compromise

TypeIndicatorContext
DOMAIN110gongan[.]comAttacker-controlled domain that hosted the malicious Public Security Bureau-themed APK.
DOMAINalcs[.]xyttkx[.]ccSubject of the default TLS certificate packaged with Flying Eagle deployments.
DOMAINfusu[.]us[.]ciDomain on a certificate hosted by an IP named in the public safety notice.
DOMAINfusu666[.]ccHardcoded C2 domain in the malicious APK; it presented a Yx科技-branded login panel.
DOMAINh5[.]xyttkx[.]ccSubdomain identified by the certificate pivot across servers presenting matching Flying Eagle login pages.
DOMAINls[.]j2x8a[.]topDomain associated with a related login panel and certificates on identified infrastructure.
DOMAINs[.]orove[.]cnFeiying panel domain identified on the open-directory server.
DOMAINtxl[.]xyttkx[.]ccSubdomain identified by the certificate pivot across servers presenting matching Flying Eagle login pages.
IPV4108[.]187[.]7[.]66Server identified through an associated certificate and hosting a related login panel.
IPV4108[.]187[.]7[.]71Server identified through an associated certificate and hosting a related login panel.
IPV4154[.]44[.]25[.]12IP paired with an AnyDesk license key found on the open-directory server; listed as investigation infrastructure.
IPV4207[.]56[.]30[.]188IP named in the public safety notice; the article says Flying Eagle malware's hardcoded C2 domain resolved to it.
IPV4207[.]56[.]30[.]194IP named in the public safety notice that hosted certificates for associated domains and an APK Confusion Manager panel.
IPV477[.]105[.]161[.]235Open-directory server containing a Windows deployment of the Flying Eagle codebase and related artifacts.
IPV485[.]137[.]253[.]48Host from which the open-directory server fetched PHP-CGI exploit code, observed on port 8000.
SHA2560376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131fHash of the Flying Eagle APK generation script ApkBuilder.php.
SHA2561456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57aHash of net.emulator.anonymizer.executor.apk bundled with the distributed Flying Eagle archive.
SHA2564395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164Hash of net.extractor.terminator.channel.apk bundled with the distributed Flying Eagle archive.
SHA2565dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095bHash of com.sequencer.classifier.processor.apk bundled with the distributed Flying Eagle archive.
SHA256773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0dfHash of a Flying Eagle APK generated during the researchers' local test.
SHA2567fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7afHash of BTMOB.exe hosted in the Flying Eagle-related open directory.
SHA25682520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7Hash of the password-protected BTMOB v4.5.5.zip archive uploaded by Yx Technology.
SHA256b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3Hash of net.cataloger.curator.stager.apk bundled with the distributed Flying Eagle archive.
SHA256c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bdHash of autoclicker_pro.apk, delivered through 110gongan[.]com.
SHA256d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86eHash of net.listener.transactor.authorizer.apk bundled with the distributed Flying Eagle archive.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles