Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
AI Summary
The article details the discovery and analysis of a malicious Android Remote Access Tool (RAT) framework called Flying Eagle, which was leaked in early 2026 and has since been widely distributed by cybercriminal actors. The malware is distributed via fake apps impersonating Chinese government services and includes capabilities for credential theft, keylogging, screen capture, and phishing overlays. At least 170 active servers hosting the Flying Eagle infrastructure were identified, primarily in Hong Kong, using shared codebases and panel fingerprints. A new successor platform named Night Dragon has emerged, developed by the threat actor behind the @SQLRCE0 Telegram channel, indicating ongoing evolution of this mobile threat ecosystem.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 32 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 207[.]56[.]30[.]188 | Details → |
| IP | 207[.]56[.]30[.]194 | Details → |
| IP | 108[.]187[.]7[.]66 | Details → |
| IP | 108[.]187[.]7[.]71 | Details → |
| IP | 77[.]105[.]161[.]235 | Details → |
| IP | 154[.]44[.]25[.]12 | Details → |
| IP | 85[.]137[.]253[.]48 | Details → |
| Domain | 110gongan[.]com | Details → |
| Domain | fusu[.]us[.]ci | Details → |
| Domain | ls[.]j2x8a[.]top | Details → |
| Domain | alcs[.]xyttkx[.]cc | Details → |
| Domain | txl[.]xyttkx[.]cc | Details → |
| Domain | h5[.]xyttkx[.]cc | Details → |
| Domain | s[.]orove[.]cn | Details → |
| Filename | SECRIT_KEY | Details → |
| Filename | Eaod85401.php | Details → |
| Filename | Eaod29251.php | Details → |
| Filename | EaodWorker.exe | Details → |
| Filename | ApkBuilder.php | Details → |
| Package | com.icontrol.protector | Details → |
| GitHub Repo | 中国龙.zip | Details → |
| GitHub Repo | 飞鹰控打包.zip | Details → |
| SHA-256 | c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd | Details → |
| SHA-256 | 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f | Details → |
| SHA-256 | 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 | Details → |
| SHA-256 | 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b | Details → |
| SHA-256 | b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 | Details → |
| SHA-256 | d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e | Details → |
| SHA-256 | 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a | Details → |
| SHA-256 | 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df | Details → |
| SHA-256 | 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 | Details → |
| SHA-512 | 7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af | Details → |