Leaked Android RAT used in attacks by 170 servers, successor emerging
Key Takeaways A leaked Android Remote Access Trojan (RAT) named Flying Eagle is actively being used by criminal networks across at least 170 servers globally. Flying Eagle allows attackers to create...
Key Takeaways
- A leaked Android Remote Access Trojan (RAT) named Flying Eagle is actively being used by criminal networks across at least 170 servers globally.
- Flying Eagle allows attackers to create convincing fake Android applications, seize control of infected devices, and exfiltrate sensitive data for financial fraud.
- A successor RAT, “Night Dragon,” has emerged from the same criminal channels, demonstrating rapid malware evolution and deployment.
- Attackers leverage themes like fake government services, financial apps, and social media to trick users into installing the malware.
- Users are at risk of extensive data theft, including keystrokes, screen captures, camera access, and phishing overlays for banking and cryptocurrency services.
Widespread Android RAT “Flying Eagle” Fuels Global Cybercrime, Successor “Night Dragon” Emerges
A significant and expanding cybercriminal operation is leveraging a leaked Android Remote Access Trojan (RAT) known as Flying Eagle. This sophisticated toolkit enables malicious actors to craft deceptive Android applications, commandeer compromised mobile devices, and steal valuable personal and financial information, leading to widespread fraud.
Table Of Content
The campaign has notably deployed applications masquerading as official Chinese Public Security Bureau services. These fake government apps are particularly effective lures, exploiting a sense of urgency and trust that often leads victims to bypass critical security warnings during installation.
Flying Eagle: A Comprehensive Attack Framework
Analysts at Hunt.io said in a report that they uncovered the malware after tracing a malicious Android Package Kit (APK) back to attacker-controlled domains and Telegram channels. These channels were not only distributing the Flying Eagle source code but also providing technical support and tools for deploying and monetizing infections.
Flying Eagle is more than just a malicious application; it functions as a full-fledged framework. It provides operators with the capability to build highly customizable Android packages and manage infected devices through a web-based control panel. The builder component allows for dynamic changes to app names, icons, package identifiers, and command-and-control (C2) addresses before generating a signed APK.
The malware utilizes diverse templates, impersonating legitimate financial applications, adult streaming services, popular social media platforms, and various public service portals. This adaptability mirrors tactics seen in other fraudulent emergency alert app campaigns, where legitimate-looking themes are used to pressure victims into installing malicious software.
Once installed, Flying Eagle exploits Android Accessibility Services to perform a range of intrusive actions. These include capturing screen content, logging keystrokes, accessing device cameras, and displaying fake login pages over legitimate applications to steal credentials. This type of permission abuse is a known tactic, as seen in Android banking overlay threat, underscoring the importance of scrutinizing app permissions.
The Flying Eagle source code was reportedly compromised in early 2026, alongside approximately 200 customer databases. Subsequently, two Telegram channels, “SQLRCE0” and “Yx Technology,” began distributing patched versions of the RAT, offering technical support and specialized tools to assist other operators in deploying and exploiting infections.
Researchers identified a staggering 170 active servers comprising the Flying Eagle infrastructure. This count includes 158 servers detected through panel fingerprinting and certificate searches, plus an additional 12 unique systems employing the framework’s default TLS certificate. While the infrastructure is heavily concentrated in Hong Kong-hosted networks, servers have also been observed in the United States, mainland China, Finland, Malaysia, Canada, and Japan. This dispersed hosting strategy makes traditional domain blocking less effective, as threat actors frequently change certificates and hosting locations.
Night Dragon Emerges as a Successor
In a concerning development, the “SQLRCE0” Telegram channel introduced “Night Dragon” on June 23, 2026, presenting it as a newly developed Android remote-control kit. This successor project boasts features such as password capture for banking and payment applications, the ability to hide its icon post-installation, and a fake system-update screen designed to obscure malicious activities from the user.
During their investigation, researchers located only two active Night Dragon servers. However, given the platform’s recent launch and the ongoing development of version 2, its adoption is expected to grow. One exposed management panel revealed 46 online devices with 29 actively connected, though it was not definitively confirmed whether these represented actual victims or test data.
The Night Dragon panel offers extensive control over infected devices, including access to live screens, text messages, photos, audio recording, cameras, and files. Crucially, it can also deploy sophisticated phishing overlays targeting payment services, banks, and cryptocurrency wallets, posing a severe threat to individuals engaged in mobile financial transactions.
The persistent availability of the leaked Flying Eagle codebase means that simply disrupting individual servers or channels is unlikely to eradicate the threat. The continuous distribution of Flying Eagle, coupled with the emergence of Night Dragon, indicates that threat actors can rapidly re-establish their operations with new branding, infrastructure, and deceptive tactics.
What You Should Do
- Install Apps from Official Sources Only: Download Android applications exclusively from trusted platforms like the Google Play Store. Avoid third-party app stores or direct APK downloads from unfamiliar websites or links.
- Verify Developer Identity: Before installing any app, especially if prompted to download it outside of official stores, thoroughly research the developer. Look for legitimate websites, reviews, and contact information.
- Review App Permissions Carefully: Pay close attention to the permissions requested by applications during installation. Be highly suspicious of apps requesting extensive permissions, such as Accessibility Services or SMS access, especially if they seem unrelated to the app’s stated function.
- Enable Google Play Protect: Ensure Google Play Protect is active on your Android device. It automatically scans apps for malware before and after installation.
- Keep Your Device and Apps Updated: Regularly install security updates for your Android operating system and all installed applications to patch known vulnerabilities.
- Monitor for Suspicious Activity: Be alert for unusual battery drain, unexpected pop-ups, strange app behavior, or unsolicited messages, which could indicate a malware infection.
- Organizations: Implement Threat Intelligence: Monitor for the provided Indicators of Compromise (IoCs), including IP addresses, domains, TLS certificate fingerprints, and panel fingerprints. Integrate these into your SIEM or threat intelligence platforms.
- Educate Users: Conduct regular cybersecurity awareness training for employees on social engineering tactics, phishing, and the dangers of sideloading applications or granting excessive permissions.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| IP address | 207.56.30.188 |
Named in the June 2026 public-safety notice; hosted by Zillion Network in Hong Kong. <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ae460e6a-097f-48e0-82cd-6b2d3078d4a0/A-Leaked-Android-RAT-Is-Powering-170-Servers-and-Its-Successor-Is-Already-Online.pdf?AWSAccessKeyId=ASIA2F3EMEYE3JC5JP6B&Signature=x0VlRYLGUV3aKX1J2sF5nu%2BFeYE%3D&x-amz-security-token=IQoJb3JpZ2luX2VjELP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIEvpNqkQPIl4cOfNSkyc9qJ780Fk7zzgxetfturTxdl7AiAOG4JgEMIV5UUrR8Lfs4S4cX7W%2BJacXbcm797EHhOLCyrzBAh7EAEaDDY5OTc1MzMwOTcwNSIMnMBY%2FGq9JCOXNLseKtAEkpXLu5%2FDX1f00SqcISFRcx%2FoLjtWVXrgs3re9pr%2Fci7h%2FizZoINDXIiwKyTL5CPMVxxyw12DX9BhYFm59gXFvUTcQ0r9X0RWvDz6QM63CklCgg0l%2FvrJnAaQvloa2ssZCDIhASvEbf0M8iFRGOxViV3gi9TkjrPeiS9nNROoIlYVSnJz3alqvZ8VLszvq1fRJtHSrn4gT5YbfMWmwwW%2BmyAi2rSML2zabs%2FSxuA%2BX76avV06r%2F0RaLA9daFXPfhUwytlm0sYmTfah5VDoZzlQrB1vZkNNq0H2J%2BF%2BGL51j5GZdf8sMoKQ%2BvMggHevIN7xO6%2Brb5IrnklML0sCS%2BLSKx4MxsAzk1SPxi46R0BgyIXZaxCy0xPBkcjFt39waOS%2FkaNP%2B%2Bc3bqM74O2sA2l3k%2F7TrEtyMcapYjRzOeHL2MRpCMG3DQ8PDTLQ4NmGlRiQLBpszrXZupYbIU68oTpzk3JZ5tbXttQ5Rj4osfKKuVC90mEzHqZaNY8Okajmc%2B3y8VrQMxdV4of91%2F00CXqlY9NhWoU%2BahHNEZyvrxtlFC1Ppv4E501hZgeZiFkfnIY%2FG3tZIIDwAyUMVb5OmMdPh6%2BO696moEDbunCFKG%2BmzuNSWtf8IQJmKfZggHbAoEKBzIghPYvqhBgaFQ8D6lhjR87jiYL6QbKZaPwun%2B13wMdkKTlExrBB9AlQeeM2OAZrIwsDqX4seHBpUEVEU%2BlG%2F0XnT3Q83V3HcDxDVeKvc9RbHs4mzja8%2BFJuT7ScFu%2B2%2FkWbe8piKOaaDqYwiuoUTDEoqfTBjqZAbJjai8ZKWOM9F1OLFj26%2Fel%2BL1VdDqQcYThrnwOQAf0NOTKdD%2FvuxvSmwWu%2FYzOZcwatMbf8qfj0cy7T77oreNU1oKsvSGCDmfuj93oA0LYa6oEedqo6PN81CXubekMqOIm1o%2BCdfFaGpSbuXPrnQ1o1WiEHU0ectxPqHGkBm
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.