Flying Eagle RAT Exploits Android Accessibility for Widespread Surveillance
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Flying Eagle Android RAT has been identified as a significant threat, utilizing Accessibility Services to conduct extensive surveillance, credential theft, and remote manipulation of devices. It primarily targets users through fraudulent applications masquerading as official Public Security Bureau apps. The malware has been linked to the theft of nearly 200 customer databases and the release of its source code in early 2026. A successor, Night Dragon, was launched on June 23, 2026, enhancing its capabilities with features like black-screen mode and automatic icon hiding. A public warning was issued by Chinese state media on June 18, 2026, confirming the ongoing campaign. The malware affects Android devices and poses a serious risk to banking and personal information. Current distribution methods include patched builds available through two Telegram channels. The situation remains active and concerning for users and security professionals alike.
Key Points: • Flying Eagle RAT uses Accessibility Services for extensive device surveillance and manipulation. • The malware was distributed via fake Public Security Bureau applications targeting Android users. • A successor, Night Dragon, enhances the RAT's capabilities and has been active since June 23, 2026.