Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Flying Eagle Android RAT Found on 170 Servers

Flying Eagle Android RAT Found on 170 Servers

Posted on July 29, 2026 By CWS

The Flying Eagle Android remote access trojan (RAT) has been discovered on numerous servers as its source code circulates on criminal Telegram channels. Researchers from Hunt.io, alongside independent analyst NetAskari, linked the trojan’s control panels and certificates to 170 servers across the internet.

Framework Targeting Android Users

The framework has been associated with a counterfeit Public Security service app known as ‘公安一网通办,’ specifically targeting Android users in China. This malicious toolkit is equipped with capabilities to capture payment passwords and keystrokes, record screens, access cameras, and initiate phishing attacks on financial, adult-content, and government-related applications.

In a detailed examination covering a month’s telemetry, Hunt.io identified infrastructure patterns on 170 servers. However, this number does not necessarily equate to a similar number of compromised devices, victims, or command-and-control systems.

Infrastructure and Distribution

The identification of 158 servers was facilitated by analyzing AdminPro page titles, HTTPS redirect behaviors, and response headers, with an additional 12 servers linked via a default certificate found with Flying Eagle. The researchers caution that these figures might be understated, as similar servers without the expected redirects were not included.

Chinese authorities have strongly advised users who downloaded the fraudulent application to uninstall it immediately, perform device scans, change passwords, freeze payment channels if unauthorized transactions are detected, and report the incident to law enforcement.

Research Findings and Recommendations

On June 18, China’s National Cybersecurity Notification Center alerted the public about the fake app’s distribution from 110gongan[.]com, connected to IP address 207.56.30[.]188, which posed a risk of data theft and remote device control. Further research published on July 28 revealed that the Flying Eagle code, distributed as a 388 MB archive named 中国龙.zip (‘Chinese Dragon’), comes with comprehensive deployment tools including nginx, PHP, MySQL, and Android build tools.

Hunt.io’s analysis indicates the builder framework is recognized as SpyNote, exploiting Android accessibility services for privilege escalation. Reports also show active distribution via two Telegram channels, SQLRCE0 and Yx Technology, though claims of infrastructure compromise involving 189 servers remain unverified.

Despite the documented server presence and code distribution, no direct link between these factors has been established. The emergence of a separate Android control kit, Night Dragon, indicates ongoing developments in Android-targeted crimeware. Researchers note that Night Dragon, unrelated to the 2011 espionage campaign by the same name, is financially driven and currently under further development.

The growing presence of Flying Eagle and related threats underscores the need for heightened vigilance and preventive measures among Android users and cybersecurity professionals.

The Hacker News Tags:Android security, China, Cybercrime, Cybersecurity, Flying Eagle RAT, malware analysis, mobile security, network threats, source code, threat intelligence

Post navigation

Previous Post: Hackers Embed Commands in Emails to Exploit AI Systems
Next Post: Minnesota Water Systems Hit by Coordinated Cyberattacks

Related Posts

IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More The Hacker News
Vercel Data Breach, DDoS Takedown, New Android Threats Vercel Data Breach, DDoS Takedown, New Android Threats The Hacker News
ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands The Hacker News
KadNap Malware Uses Asus Routers for Stealth Botnet KadNap Malware Uses Asus Routers for Stealth Botnet The Hacker News
The Unusual Suspect: Git Repos The Unusual Suspect: Git Repos The Hacker News
Cyber Espionage Threatens Asian Infrastructure via Web Exploits Cyber Espionage Threatens Asian Infrastructure via Web Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Minnesota Water Systems Hit by Coordinated Cyberattacks
  • Flying Eagle Android RAT Found on 170 Servers
  • Hackers Embed Commands in Emails to Exploit AI Systems
  • AI Agent Breaches Highlight Security Risks at Hugging Face
  • Malicious npm Packages Target Alibaba Developers with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Minnesota Water Systems Hit by Coordinated Cyberattacks
  • Flying Eagle Android RAT Found on 170 Servers
  • Hackers Embed Commands in Emails to Exploit AI Systems
  • AI Agent Breaches Highlight Security Risks at Hugging Face
  • Malicious npm Packages Target Alibaba Developers with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark