Skip to content
Data Breach

A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online

A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create fake Android apps, take control of infected phones, and steal information that can lead to financial fraud. The campaign used apps disguised as Chine...

· Jul 29, 2026 · 7 min read · 👁 0 views
A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online

A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network.

The toolkit lets operators create fake Android apps, take control of infected phones, and steal information that can lead to financial fraud.

The campaign used apps disguised as Chinese Public Security Bureau services to reach potential victims.

Fake government apps remain an effective lure because they create urgency and can make people overlook warning signs during installation.

Hunt.io analysts identified the malware after tracing a malicious APK to attacker-controlled domains and Telegram channels that distributed the Flying Eagle source code.

Hunt.io said in a report shared with Cyber Security News (CSN) that their investigation found a leaked builder and device-control framework that had already been adapted by several criminal actors.

Login panel (Source - Hunt.io)
Login panel (Source – Hunt.io)

The scale is notable, as the researchers identified 170 servers linked to Flying Eagle infrastructure, while the actors behind a related Telegram channel have introduced Night Dragon, a newer Android RAT that appears to be moving toward wider use.

A Leaked Android RAT Is Powering 170 Servers

Flying Eagle is not just a malicious app. It is a complete framework that allows an operator to build customized Android packages and manage compromised devices from a web panel.

The builder can change app names, icons, package names, and command-and-control addresses before producing a signed APK.

APK generation page in a local test instance (Source - Hunt.io)
APK generation page in a local test instance (Source – Hunt.io)

The malware’s templates imitate financial apps, adult streaming services, social media platforms, and public-service portals.

That flexibility reflects a pattern seen in fraudulent emergency alert app campaigns, where trusted-looking themes are used to push victims into installing harmful software.

Once installed, Flying Eagle can abuse Android Accessibility Services, capture screens, log keystrokes, access the camera, and display fake login pages over legitimate apps.

Similar permission abuse has featured in the Android banking overlay threat, highlighting why users should carefully review access requests before enabling them.

The source code was reportedly stolen in early 2026 along with nearly 200 customer databases.

Two Telegram channels, SQLRCE0 and Yx Technology, then distributed patched versions, technical assistance, and tools designed to help operators deploy and monetize infections.

The Hunt.io’s panel fingerprinting and certificate searches identified 158 Flying Eagle servers, plus 12 additional unique systems using the framework’s default TLS certificate.

The infrastructure was concentrated in Hong Kong-hosted networks, although servers were also observed in the United States, mainland China, Finland, Malaysia, Canada, and Japan.

This spread makes simple domain blocking less reliable, especially when operators regularly rotate certificates and hosting locations.

Night Dragon Emerges

Night Dragon was introduced by SQLRCE0 on June 23, 2026, as a separately developed Android remote-control kit.

The project was described as supporting password capture for banking and payment apps, icon hiding after installation, and a fake system-update screen intended to conceal attacker activity.

Test login page for Flying Eagle (Source - Hunt.io)
Test login page for Flying Eagle (Source – Hunt.io)

Researchers found only two active Night Dragon servers during the investigation, but the platform was still new and version 2 was already in development.

One exposed management panel showed 46 devices online and 29 actively connected, although the researchers could not confirm whether the displayed records were real victims or test data.

The panel offered access to live screens, text messages, photos, audio recording, cameras, and files.

It could also push phishing overlays for payment services, banks, and cryptocurrency wallets, making it especially dangerous for people who use mobile devices for financial activity.

Login page hosted at fusu666[.]cc, including Yx科技 (YxTechnology) in the upper right corner (Source - Hunt.io)
Login page hosted at fusu666[.]cc, including Yx科技 (YxTechnology) in the upper right corner (Source – Hunt.io)

The campaign shows why Android users should install apps only from official stores, verify the developer behind unfamiliar software, and reject unexpected Accessibility Service or SMS permissions.

Organizations should also monitor for the panel fingerprints and network indicators below, while reviewing suspicious mobile activity alongside Telegram phishing authentication attacks and other social-engineering threats.

The leaked codebase means Flying Eagle is unlikely to disappear when a single server or channel is removed. Its continued distribution, combined with Night Dragon’s arrival, suggests that operators can quickly rebuild campaigns with new branding, infrastructure, and lures.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
IP address207.56.30.188Named in the June 2026 public-safety notice; hosted by Zillion Network in Hong Kong. 
IP address207.56.30.194Named in the notice; hosted rotating certificates and an APK Confusion Manager panel. 
IP address108.187.7.66Flying Eagle-style login panel on port 443. 
IP address108.187.7.71Flying Eagle-style login panel on port 443. 
IP address and port77.105.161.235:8000Open directory containing an XAMPP deployment of the shared Flying Eagle codebase. 
IP address154.44.25.12Paired with an AnyDesk license key found in the exposed directory. 
IP address and port85.137.253.48:8000Hosted PHP-CGI exploit code fetched by the open-directory host. 
Domain110gongan.comHosted the malicious APK impersonating a public-security service. 
Domainfusu.us.ciObserved on a TLS certificate hosted by 207.56.30.194
Domainfusu666.ccHardcoded command-and-control domain in the malicious APK. 
Domainls.j2x8a.topCertificate-linked domain with a Flying Eagle-related login panel. 
Domainalcs.xyttkx.ccSubject common name of the default TLS certificate packaged with Flying Eagle. 
Domaintxl.xyttkx.ccReturned through a certificate pivot on xyttkx.cc
Domainh5.xyttkx.ccReturned through a certificate pivot on xyttkx.cc
Domains.orove.cnFeiying/Flying Eagle panel domain found in the exposed directory. 
TLS certificate SHA-1AB4224A6361E6F826FDB262276411E03F8177E30Default Flying Eagle certificate fingerprint. 
TLS certificate serial06E54E9528F4F8CFEBDC486D78C65B46212ESerial number of the default packaged TLS certificate. 
Package namecom.icontrol.protectorHardcoded default Android package name replaced during APK generation. 
ArtifactSECRITKEYMisspelled environment variable used to pivot to the exposed deployment. 
FilenameEaod85401.phpPHP file found in Docker and XAMPP Flying Eagle deployments. 
FilenameEaod29251.phpPHP file found in Docker and XAMPP Flying Eagle deployments. 
FilenameEaodWorker.exeOriginal Windows .NET binary referenced in builder comments. 
FilenameApkBuilder.phpAPK-generation script used for renaming, obfuscation, URL encryption, and padding. 
Filenameautoclickerpro.apkMalicious APK delivered through 110gongan.com
Filenamenet.extractor.terminator.channel.apkAPK bundled in the leaked Flying Eagle archive. 
SHA-256c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bdHash for ApkBuilder.php
SHA-2560376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131fHash for net.extractor.terminator.channel.apk
SHA-2564395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164Hash for com.sequencer.classifier.processor.apk
SHA-2565dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095bHash for net.cataloger.curator.stager.apk
SHA-256b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3Hash for net.listener.transactor.authorizer.apk
SHA-256d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86eHash for net.emulator.anonymizer.executor.apk
SHA-2561456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57aHash for org.merger.refactor.module.apk
SHA-256773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0dfHash for the BTMOB v4.5.5.zip archive. 
SHA-25682520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7Hash for BTMOB.exe hosted on the exposed directory. 
Telegram handleSQLRCE0Channel that distributed patched Flying Eagle builds and introduced Night Dragon. 
Telegram handleYx TechnologyChannel that distributed Flying Eagle, BTMOB RAT, and related tooling. 
Panel fingerprintAdminProHTML page title observed on Flying Eagle panels. 
Panel fingerprintlogin?redirectlistbasic-listLogin route associated with Flying Eagle infrastructure. 
Panel fingerprintStrict-Transport-Security: max-age=31536000Header associated with the Flying Eagle HTTP-to-HTTPS redirect pattern. 
Panel fingerprintSQLRCEHTML title observed on related SQLRCE panels. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you