A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network.
The toolkit lets operators create fake Android apps, take control of infected phones, and steal information that can lead to financial fraud.
The campaign used apps disguised as Chinese Public Security Bureau services to reach potential victims.
Fake government apps remain an effective lure because they create urgency and can make people overlook warning signs during installation.
Hunt.io analysts identified the malware after tracing a malicious APK to attacker-controlled domains and Telegram channels that distributed the Flying Eagle source code.
Hunt.io said in a report shared with Cyber Security News (CSN) that their investigation found a leaked builder and device-control framework that had already been adapted by several criminal actors.

The scale is notable, as the researchers identified 170 servers linked to Flying Eagle infrastructure, while the actors behind a related Telegram channel have introduced Night Dragon, a newer Android RAT that appears to be moving toward wider use.
A Leaked Android RAT Is Powering 170 Servers
Flying Eagle is not just a malicious app. It is a complete framework that allows an operator to build customized Android packages and manage compromised devices from a web panel.
The builder can change app names, icons, package names, and command-and-control addresses before producing a signed APK.

The malware’s templates imitate financial apps, adult streaming services, social media platforms, and public-service portals.
That flexibility reflects a pattern seen in fraudulent emergency alert app campaigns, where trusted-looking themes are used to push victims into installing harmful software.
Once installed, Flying Eagle can abuse Android Accessibility Services, capture screens, log keystrokes, access the camera, and display fake login pages over legitimate apps.
Similar permission abuse has featured in the Android banking overlay threat, highlighting why users should carefully review access requests before enabling them.
The source code was reportedly stolen in early 2026 along with nearly 200 customer databases.
Two Telegram channels, SQLRCE0 and Yx Technology, then distributed patched versions, technical assistance, and tools designed to help operators deploy and monetize infections.
The Hunt.io’s panel fingerprinting and certificate searches identified 158 Flying Eagle servers, plus 12 additional unique systems using the framework’s default TLS certificate.
The infrastructure was concentrated in Hong Kong-hosted networks, although servers were also observed in the United States, mainland China, Finland, Malaysia, Canada, and Japan.
This spread makes simple domain blocking less reliable, especially when operators regularly rotate certificates and hosting locations.
Night Dragon Emerges
Night Dragon was introduced by SQLRCE0 on June 23, 2026, as a separately developed Android remote-control kit.
The project was described as supporting password capture for banking and payment apps, icon hiding after installation, and a fake system-update screen intended to conceal attacker activity.

Researchers found only two active Night Dragon servers during the investigation, but the platform was still new and version 2 was already in development.
One exposed management panel showed 46 devices online and 29 actively connected, although the researchers could not confirm whether the displayed records were real victims or test data.
The panel offered access to live screens, text messages, photos, audio recording, cameras, and files.
It could also push phishing overlays for payment services, banks, and cryptocurrency wallets, making it especially dangerous for people who use mobile devices for financial activity.
![Login page hosted at fusu666[.]cc, including Yx科技 (YxTechnology) in the upper right corner (Source - Hunt.io)](https://blog.shomoysoft.com/storage/blog-images/login20page20hosted20at20fusu6665b5dcc20including20yxe7a791e68a8020yxtechnology20in20the20upper20right20corner20source20-20huntio-108bc6fd.webp)
The campaign shows why Android users should install apps only from official stores, verify the developer behind unfamiliar software, and reject unexpected Accessibility Service or SMS permissions.
Organizations should also monitor for the panel fingerprints and network indicators below, while reviewing suspicious mobile activity alongside Telegram phishing authentication attacks and other social-engineering threats.
The leaked codebase means Flying Eagle is unlikely to disappear when a single server or channel is removed. Its continued distribution, combined with Night Dragon’s arrival, suggests that operators can quickly rebuild campaigns with new branding, infrastructure, and lures.
Indicators of Compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.