Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

·
Listen to this article~4 min
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels. Hunt.io and NetAskari traced it to 170 servers, linked to a fake government app targeting Android users in China.

A dangerous new threat is quietly spreading through criminal Telegram channels, and it's targeting Android users with a fake government app. The source code for the Flying Eagle Android remote access trojan (RAT) framework has been leaked, and security researchers are sounding the alarm. Hunt.io, along with independent researcher NetAskari, dug into this mess and found something unsettling. They traced matching control panels and digital certificates to over 170 internet servers scattered around the globe. That's not a small operation—it's a sign that this malware is being actively deployed. ### What Is the Flying Eagle RAT? This isn't just any malware. The Flying Eagle RAT is a sophisticated framework that gives attackers full remote control over infected Android devices. Think of it as a digital skeleton key. Once it's on your phone, it can steal payment passwords, track your location, read your messages, and even record audio. The framework was linked to a fake app pretending to be a "公安一网通办" (Public Security One-Stop Service) application. This is a government service app in China, so the disguise is clever and dangerous. Victims think they're installing something official, but they're actually handing over the keys to their digital life. ### The Scope of the Attack Here's what makes this situation so serious: the source code is now circulating openly in criminal forums. That means anyone with basic technical skills can grab it and start building their own version of the RAT. And with 170 servers already identified, the infrastructure is ready to go. - **170 servers** hosting control panels and certificates - **Fake government app** used as a lure - **Source code leaked** on Telegram channels - **Payment-password theft** is a core feature This isn't just a Chinese problem. The servers are spread across multiple countries, and the attackers are likely targeting users worldwide. If you're an Android user, this is something to pay attention to. ### How Does the Malware Spread? The primary method is social engineering. Attackers create fake websites that look like official government portals. They then promote these sites through phishing emails, SMS messages, and even direct messages on social media. The fake "公安一网通办" app is just one example. Once a user downloads and installs the app, the RAT takes over. It requests permissions that seem normal—like access to storage, camera, and microphone—but then uses them for malicious purposes. The payment-password feature is particularly nasty: it can intercept what you type into banking apps or payment services. ### What Should You Do? Right now, the best defense is awareness. If you get a message urging you to download a government app, don't click. Go directly to the official website instead. And always check app permissions carefully—if a simple utility app wants access to your contacts and messages, that's a red flag. For businesses, this is a reminder to keep Android devices updated and to use mobile security solutions. The Flying Eagle RAT is just one example of a growing trend where leaked source code makes powerful malware accessible to anyone. ### The Bigger Picture This situation highlights a shift in the cybercrime landscape. It's not just about sophisticated groups anymore. With source code like this circulating, even low-skill attackers can launch serious operations. The 170 servers found by Hunt.io and NetAskari might just be the tip of the iceberg. We'll likely see more variants of this RAT in the coming months. The key takeaway is simple: stay vigilant, verify before you install, and never trust unsolicited app downloads. Because once the Flying Eagle lands on your device, it's already too late.