Essential Insights
- The Flying Eagle Android RAT framework, circulated via criminal Telegram channels, enables payment-password theft, keystroke capture, screen recording, and camera access, targeting Chinese users with fake security apps.
- Researchers identified 170 servers hosting Flying Eagle control panels and certificates, primarily linked to a fake public security app, indicating widespread distribution and infrastructure.
- Modified versions of Flying Eagle and its control kits, like Night Dragon, are being promoted in Telegram channels, with capabilities for privilege escalation, data exfiltration, and cybercrime revenue through cash-out services.
Threat, Techniques, and Targets
The Flying Eagle Android RAT framework is now found on 170 internet servers, based on recent research. Its source code is circulating on criminal Telegram channels. The framework is linked to a fake “公安一网通办” public security app used in China. The malware can capture payment passwords, keystrokes, record screens, access device cameras, and send phishing prompts. It mainly targets Android users in China, especially those dealing with financial, adult-content, and government services. The operators can customize the app’s name, icon, and C2 server address. They generate a signed APK file with encryption and padding to hide malicious code. The control panel is built with various web tools and can be used for remote device management. Researchers found the control code is used in other malware, like SpyNote. Distributors of the malware are active on Telegram, claiming they have compromised servers and exfiltrated data. Although 170 servers are identified, this does not confirm 170 infected phones or victims.
Impact, Implications, and Guidance
The circulation of Flying Eagle source code increases the threat to Android users in China. The malware can remotely control devices and steal sensitive data. This creates serious security risks for individuals and institutions. The use of multiple servers makes it harder to block attacks. Chinese authorities advise users who installed the fake app to remove it, scan their devices, change passwords, and report incidents to police. The Chinese Cybersecurity Center warns the app can steal payment data and give attackers control over devices. Because detailed remediation guidance is not provided in the report, users and organizations should seek advice from their device vendors or cybersecurity authorities. It is important to keep systems updated and to be cautious about installing untrusted apps or clicking on suspicious links.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
