hacker-news · Crawled Jul 29, 2026

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

6 IoCs 1 Actors
Read original article ↗

AI Summary

The source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, enabling widespread deployment of the malware. Researchers identified infrastructure linked to 170 servers hosting control panels or certificates associated with the RAT, which is used in a fake Chinese Public Security app called '公安一网通办'. The malware can steal payment credentials, record screens, access cameras, and perform phishing attacks on financial and government apps. A second Android RAT, Night Dragon, was introduced by one of the same Telegram groups, though it appears to be a separate build with no shared code with Flying Eagle.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain 110gongan[.]com Details →
IP 207[.]56[.]30[.]188 Details →
Filename 中国龙.zip Details →
Filename Chinese Dragon Details →
GitHub Repo SQLRCE0 Details →
GitHub Repo Yx Technology Details →

MITRE ATT&CK TTPs 6 techniques