hacker-news · Crawled Jul 29, 2026
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
6 IoCs 1 Actors
Read original article ↗
AI Summary
The source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, enabling widespread deployment of the malware. Researchers identified infrastructure linked to 170 servers hosting control panels or certificates associated with the RAT, which is used in a fake Chinese Public Security app called '公安一网通办'. The malware can steal payment credentials, record screens, access cameras, and perform phishing attacks on financial and government apps. A second Android RAT, Night Dragon, was introduced by one of the same Telegram groups, though it appears to be a separate build with no shared code with Flying Eagle.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 6 extracted
MITRE ATT&CK TTPs 6 techniques
T1003 OS Credential Dumping · Credential Access T1059 Command and Scripting Interpreter · Execution T1071.001 Web Protocols · Command And Control T1133 External Remote Services · Persistence T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion