A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network.

The toolkit lets operators create fake Android apps, take control of infected phones, and steal information that can lead to financial fraud.

The campaign used apps disguised as Chinese Public Security Bureau services to reach potential victims.

Fake government apps remain an effective lure because they create urgency and can make people overlook warning signs during installation.

Hunt.io analysts identified the malware after tracing a malicious APK to attacker-controlled domains and Telegram channels that distributed the Flying Eagle source code.

Hunt.io said in a report shared with Cyber Security News (CSN) that their investigation found a leaked builder and device-control framework that had already been adapted by several criminal actors.

Login panel (Source – Hunt.io)

The scale is notable, as the researchers identified 170 servers linked to Flying Eagle infrastructure, while the actors behind a related Telegram channel have introduced Night Dragon, a newer Android RAT that appears to be moving toward wider use.

A Leaked Android RAT Is Powering 170 Servers

Flying Eagle is not just a malicious app. It is a complete framework that allows an operator to build customized Android packages and manage compromised devices from a web panel.

The builder can change app names, icons, package names, and command-and-control addresses before producing a signed APK.

APK generation page in a local test instance (Source – Hunt.io)

The malware’s templates imitate financial apps, adult streaming services, social media platforms, and public-service portals.

That flexibility reflects a pattern seen in fraudulent emergency alert app campaigns, where trusted-looking themes are used to push victims into installing harmful software.

Once installed, Flying Eagle can abuse Android Accessibility Services, capture screens, log keystrokes, access the camera, and display fake login pages over legitimate apps.

Similar permission abuse has featured in the Android banking overlay threat, highlighting why users should carefully review access requests before enabling them.

The source code was reportedly stolen in early 2026 along with nearly 200 customer databases.

Two Telegram channels, SQLRCE0 and Yx Technology, then distributed patched versions, technical assistance, and tools designed to help operators deploy and monetize infections.

The Hunt.io’s panel fingerprinting and certificate searches identified 158 Flying Eagle servers, plus 12 additional unique systems using the framework’s default TLS certificate.

The infrastructure was concentrated in Hong Kong-hosted networks, although servers were also observed in the United States, mainland China, Finland, Malaysia, Canada, and Japan.

This spread makes simple domain blocking less reliable, especially when operators regularly rotate certificates and hosting locations.

Night Dragon Emerges

Night Dragon was introduced by SQLRCE0 on June 23, 2026, as a separately developed Android remote-control kit.

The project was described as supporting password capture for banking and payment apps, icon hiding after installation, and a fake system-update screen intended to conceal attacker activity.

Test login page for Flying Eagle (Source – Hunt.io)

Researchers found only two active Night Dragon servers during the investigation, but the platform was still new and version 2 was already in development.

One exposed management panel showed 46 devices online and 29 actively connected, although the researchers could not confirm whether the displayed records were real victims or test data.

The panel offered access to live screens, text messages, photos, audio recording, cameras, and files.

It could also push phishing overlays for payment services, banks, and cryptocurrency wallets, making it especially dangerous for people who use mobile devices for financial activity.

Login page hosted at fusu666[.]cc, including Yx科技 (YxTechnology) in the upper right corner (Source – Hunt.io)

The campaign shows why Android users should install apps only from official stores, verify the developer behind unfamiliar software, and reject unexpected Accessibility Service or SMS permissions.

Organizations should also monitor for the panel fingerprints and network indicators below, while reviewing suspicious mobile activity alongside Telegram phishing authentication attacks and other social-engineering threats.

The leaked codebase means Flying Eagle is unlikely to disappear when a single server or channel is removed. Its continued distribution, combined with Night Dragon’s arrival, suggests that operators can quickly rebuild campaigns with new branding, infrastructure, and lures.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 207.56.30.188 Named in the June 2026 public-safety notice; hosted by Zillion Network in Hong Kong. 
IP address 207.56.30.194 Named in the notice; hosted rotating certificates and an APK Confusion Manager panel. 
IP address 108.187.7.66 Flying Eagle-style login panel on port 443. 
IP address 108.187.7.71 Flying Eagle-style login panel on port 443. 
IP address and port 77.105.161.235:8000 Open directory containing an XAMPP deployment of the shared Flying Eagle codebase. 
IP address 154.44.25.12 Paired with an AnyDesk license key found in the exposed directory. 
IP address and port 85.137.253.48:8000 Hosted PHP-CGI exploit code fetched by the open-directory host. 
Domain 110gongan.com Hosted the malicious APK impersonating a public-security service. 
Domain fusu.us.ci Observed on a TLS certificate hosted by 207.56.30.194
Domain fusu666.cc Hardcoded command-and-control domain in the malicious APK. 
Domain ls.j2x8a.top Certificate-linked domain with a Flying Eagle-related login panel. 
Domain alcs.xyttkx.cc Subject common name of the default TLS certificate packaged with Flying Eagle. 
Domain txl.xyttkx.cc Returned through a certificate pivot on xyttkx.cc
Domain h5.xyttkx.cc Returned through a certificate pivot on xyttkx.cc
Domain s.orove.cn Feiying/Flying Eagle panel domain found in the exposed directory. 
TLS certificate SHA-1 AB4224A6361E6F826FDB262276411E03F8177E30 Default Flying Eagle certificate fingerprint. 
TLS certificate serial 06E54E9528F4F8CFEBDC486D78C65B46212E Serial number of the default packaged TLS certificate. 
Package name com.icontrol.protector Hardcoded default Android package name replaced during APK generation. 
Artifact SECRITKEY Misspelled environment variable used to pivot to the exposed deployment. 
Filename Eaod85401.php PHP file found in Docker and XAMPP Flying Eagle deployments. 
Filename Eaod29251.php PHP file found in Docker and XAMPP Flying Eagle deployments. 
Filename EaodWorker.exe Original Windows .NET binary referenced in builder comments. 
Filename ApkBuilder.php APK-generation script used for renaming, obfuscation, URL encryption, and padding. 
Filename autoclickerpro.apk Malicious APK delivered through 110gongan.com
Filename net.extractor.terminator.channel.apk APK bundled in the leaked Flying Eagle archive. 
SHA-256 c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd Hash for ApkBuilder.php
SHA-256 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f Hash for net.extractor.terminator.channel.apk
SHA-256 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 Hash for com.sequencer.classifier.processor.apk
SHA-256 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b Hash for net.cataloger.curator.stager.apk
SHA-256 b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 Hash for net.listener.transactor.authorizer.apk
SHA-256 d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e Hash for net.emulator.anonymizer.executor.apk
SHA-256 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a Hash for org.merger.refactor.module.apk
SHA-256 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df Hash for the BTMOB v4.5.5.zip archive. 
SHA-256 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 Hash for BTMOB.exe hosted on the exposed directory. 
Telegram handle SQLRCE0 Channel that distributed patched Flying Eagle builds and introduced Night Dragon. 
Telegram handle Yx Technology Channel that distributed Flying Eagle, BTMOB RAT, and related tooling. 
Panel fingerprint AdminPro HTML page title observed on Flying Eagle panels. 
Panel fingerprint login?redirectlistbasic-list Login route associated with Flying Eagle infrastructure. 
Panel fingerprint Strict-Transport-Security: max-age=31536000 Header associated with the Flying Eagle HTTP-to-HTTPS redirect pattern. 
Panel fingerprint SQLRCE HTML title observed on related SQLRCE panels. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.