← BACK TO FEED
TAG

spynote1 articles

Flying Eagle Android RAT Source Code Leaks, Fingerprints Spotted on 170 Servers

Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with researchers at Hunt.io and NetAskari identifying matching infrastructure on 170 internet servers, though this figure reflects server fingerprints rather than confirmed victims or active command-and-control systems. The toolkit, disguised as a fake Chinese public security app, supports keystroke and payment-password capture, screen recording, camera access, and phishing overlays, and its builder generates obfuscated APKs with encrypted C2 URLs. Researchers also identified a separate Android RAT called Night Dragon being promoted by one of the same Telegram channels, though it appears to be an independent, financially motivated tool unrelated to the 2011 espionage campaign of the same name.

29 Jul 2026