Skip to content
Flying Eagle Android RAT Targets Users with Fake Public Security Apps

Flying Eagle Android RAT Targets Users with Fake Public Security Apps

First seen 29 Jul 2026, 11:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 09:22 UTC
  • Flying Eagle RAT is distributed through fake Public Security Bureau apps targeting Android users.
  • 170 servers linked to the Flying Eagle framework have been identified, with ongoing distribution on Telegram.
  • Chinese authorities have issued warnings and recommended users to remove the fraudulent app and secure their devices.

The Flying Eagle Android remote access trojan (RAT) is being distributed via fraudulent applications impersonating China's Public Security Bureau. Researchers from Hunt.io and NetAskari identified 170 servers linked to this malware, which captures sensitive information such as payment passwords and keystrokes. The malware utilizes Android Accessibility Services for extensive device control, including screen recording and camera access. Chinese authorities have issued warnings advising users to remove the fake app and secure their devices. The source code for Flying Eagle was leaked earlier in 2026, leading to the emergence of patched variants on Telegram. A successor platform named Night Dragon is also under development, indicating a potential escalation in threat capabilities. The total server count is believed to be conservative, with ongoing distribution efforts noted in Telegram channels.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-06-18
Public warning issued by Chinese state media
CCTV confirmed the distribution of fraudulent apps masquerading as official services, urging users to be cautious.
Gbhackers
2026-06-23
Night Dragon platform introduced
A successor to Flying Eagle, named Night Dragon, was announced on Telegram, enhancing stealth features.
Reddit
2026-07-30
Flying Eagle source code circulates on Telegram
The source code for the Flying Eagle RAT framework is actively being shared on criminal Telegram channels.
Feeds.Feedburner

More articles in this cluster (4)

Following this threat?

Track Night Dragon and BTMob RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed