By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Flying Eagle Android RAT Source Code Circulates

The source code for the Flying Eagle Android remote access trojan (RAT) framework has been observed circulating within criminal Telegram channels, indicating a potential increase in its malicious use. Security researchers at Hunt.io, in collaboration with independent researcher NetAskari, have successfully traced matching control panels and digital certificates associated with the Flying Eagle RAT to a significant number of internet servers. Their investigation identified a total of 170 servers hosting this infrastructure, suggesting a widespread deployment or preparation for deployment of the RAT.
The Flying Eagle RAT framework has been linked to a specific social engineering campaign that employs a deceptive application impersonating a legitimate Chinese government service. This application is branded as "公安一网通办," which translates to "Public Security One-Stop Service." The campaign specifically targets Android users within China, leveraging the fake service application to trick individuals into installing the malicious RAT. Once installed, the Flying Eagle RAT grants attackers remote control over the infected Android devices, enabling them to steal sensitive information and conduct further malicious activities. The capabilities of the Flying Eagle RAT kit are extensive, including support for intercepting and manipulating payment passwords, which poses a direct threat to users' financial security. The circulation of its source code on Telegram lowers the barrier to entry for other threat actors, potentially leading to a proliferation of new variants and attacks leveraging this framework. The discovery highlights the ongoing challenges in combating sophisticated Android malware, particularly when its core components become publicly accessible within illicit online communities. The researchers' work in tracing the server infrastructure provides valuable intelligence for cybersecurity professionals seeking to disrupt the operations of groups utilizing this RAT. The implications of this leak extend to the broader landscape of mobile security, underscoring the need for enhanced detection and prevention mechanisms against advanced persistent threats targeting the Android ecosystem. The framework's ability to compromise payment credentials is a critical concern, as it directly impacts user trust and financial safety on mobile devices. Further analysis of the traced servers may reveal additional details about the actors behind Flying Eagle and their operational methods.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.