Flying Eagle Android RAT Spotted on 170 Servers Amid Code Leak
The Flying Eagle Android RAT source code is circulating among cybercriminals, with traces found on 170 internet servers. It targets Chinese Android users via a fake public security app.
TL;DR
- Source code for the Flying Eagle Android RAT is being shared in criminal Telegram channels.
- Researchers identified 170 servers hosting control panels linked to the malware.
- The RAT is distributed through a counterfeit '公安一网通办' app targeting Chinese users.
- It can steal payment passwords and other sensitive data from infected devices.
- Organizations should monitor for suspicious server activity and educate users on app vetting.
Cybersecurity researchers have uncovered widespread use of the Flying Eagle Android remote access trojan (RAT), with its source code now circulating in underground forums. Investigations by Hunt.io and researcher NetAskari revealed that 170 internet-connected servers are actively hosting command-and-control infrastructure tied to this malware.
The RAT is primarily distributed through a deceptive Android application mimicking China's official '公安一网通办' (Public Security Service) app. Once installed, the malware can extract sensitive information including payment passwords, posing a significant risk to victims’ financial and personal data.
Malware Distribution and Infrastructure
- The Flying Eagle RAT is distributed via a fake Android app伪装成中国官方公共服务平台.
- At least 170 servers worldwide host matching control panels used to manage infected devices.
- Researchers traced these servers using unique SSL certificates and panel fingerprints.
- The campaign appears to be geofocused, targeting predominantly Chinese-speaking Android users.
Security Implications and Recommendations
- The leaked source code lowers the barrier for threat actors to deploy customized versions of the RAT.
- Organizations with mobile user bases should enhance app store monitoring and user awareness training.
- Security teams are advised to scan network traffic for connections to known malicious server IPs.
- Android users should verify app authenticity through official channels before installation.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.