The Flying Eagle Android remote access trojan (RAT) has been discovered on numerous servers as its source code circulates on criminal Telegram channels. Researchers from Hunt.io, alongside independent analyst NetAskari, linked the trojan’s control panels and certificates to 170 servers across the internet.
Framework Targeting Android Users
The framework has been associated with a counterfeit Public Security service app known as ‘公安一网通办,’ specifically targeting Android users in China. This malicious toolkit is equipped with capabilities to capture payment passwords and keystrokes, record screens, access cameras, and initiate phishing attacks on financial, adult-content, and government-related applications.
In a detailed examination covering a month’s telemetry, Hunt.io identified infrastructure patterns on 170 servers. However, this number does not necessarily equate to a similar number of compromised devices, victims, or command-and-control systems.
Infrastructure and Distribution
The identification of 158 servers was facilitated by analyzing AdminPro page titles, HTTPS redirect behaviors, and response headers, with an additional 12 servers linked via a default certificate found with Flying Eagle. The researchers caution that these figures might be understated, as similar servers without the expected redirects were not included.
Chinese authorities have strongly advised users who downloaded the fraudulent application to uninstall it immediately, perform device scans, change passwords, freeze payment channels if unauthorized transactions are detected, and report the incident to law enforcement.
Research Findings and Recommendations
On June 18, China’s National Cybersecurity Notification Center alerted the public about the fake app’s distribution from 110gongan[.]com, connected to IP address 207.56.30[.]188, which posed a risk of data theft and remote device control. Further research published on July 28 revealed that the Flying Eagle code, distributed as a 388 MB archive named 中国龙.zip (‘Chinese Dragon’), comes with comprehensive deployment tools including nginx, PHP, MySQL, and Android build tools.
Hunt.io’s analysis indicates the builder framework is recognized as SpyNote, exploiting Android accessibility services for privilege escalation. Reports also show active distribution via two Telegram channels, SQLRCE0 and Yx Technology, though claims of infrastructure compromise involving 189 servers remain unverified.
Despite the documented server presence and code distribution, no direct link between these factors has been established. The emergence of a separate Android control kit, Night Dragon, indicates ongoing developments in Android-targeted crimeware. Researchers note that Night Dragon, unrelated to the 2011 espionage campaign by the same name, is financially driven and currently under further development.
The growing presence of Flying Eagle and related threats underscores the need for heightened vigilance and preventive measures among Android users and cybersecurity professionals.
