Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.
AI Analysis
Technical Summary
Researchers uncovered a criminal ecosystem built around Flying Eagle, an Android RAT whose source code and customer databases were stolen in early 2026. The investigation started from a malicious APK impersonating a Chinese Provincial Public Security Bureau app, revealing 170 active servers running the framework. Two Telegram channels distribute modified versions with operational support and cash-out services charging 20-50% fees. The platform integrates APK generation, command and control device management, and phishing overlays targeting financial, adult, and government sectors. In June 2026, a successor platform named Night Dragon was launched, featuring improved credential capture for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity mainly targets Chinese citizens via social engineering, though international targeting capabilities exist.
Potential Impact
The threat enables credential theft and remote access on Android devices, facilitating financial fraud, identity theft, and unauthorized access to sensitive accounts. The stolen source code and customer databases have led to widespread distribution and modification of the malware, increasing its operational scale. The introduction of Night Dragon with enhanced credential capture capabilities raises the risk of more effective theft from banking and cryptocurrency applications. The use of phishing overlays and impersonation of official apps increases the likelihood of successful social engineering attacks against victims.
Mitigation Recommendations
No official patch or remediation is available as this is a malware threat rather than a software vulnerability. Defenders should focus on detecting and blocking malicious APKs, monitoring for indicators of compromise related to Flying Eagle and Night Dragon, and educating users about phishing and social engineering risks. Network defenders should monitor for communications with known command and control servers associated with this malware. Since the source code is leaked and the malware is actively distributed, proactive threat hunting and endpoint protection are recommended.
Affected Countries
China
Indicators of Compromise
- domain: 110gongan.com
- hash: 18827998ad05c58da1d218066374fe16
- hash: 645ee92d197441684919c0b1ad5cfd15
- hash: 81694f8296ea8e589acc68382add4311
- hash: b5f64311ffe3c6f1eb13b769663702c6
- hash: d23e2d0c71cbf0a5d67e17e7b3c690e0
- hash: 5d95ddf7cd857acaaa3447e710a3ee596262b4e2
- hash: 68389a8ae359c2e730e33ab60e9fa6ad71120983
- hash: d767524b3b288f09840f3d7196718e4187515f6b
- hash: e02955f78fca6c758d760c36474ae0d4f546efb4
- hash: e9c71b51de94d6ef1f1090a36754d987374f6f70
- hash: 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f
- hash: 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a
- hash: 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164
- hash: 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b
- hash: 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df
- hash: 7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af
- hash: 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7
- hash: b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3
- hash: c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd
- hash: d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e
- ip: 108.187.7.66
- ip: 108.187.7.71
- ip: 154.44.25.12
- ip: 207.56.30.188
- ip: 207.56.30.194
- ip: 77.105.161.235
- ip: 85.137.253.48
- domain: fusu666.cc
- domain: xyttkx.cc
- domain: alcs.xyttkx.cc
- domain: h5.xyttkx.cc
- domain: ls.j2x8a.top
- domain: s.orove.cn
- domain: txl.xyttkx.cc
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Description
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers uncovered a criminal ecosystem built around Flying Eagle, an Android RAT whose source code and customer databases were stolen in early 2026. The investigation started from a malicious APK impersonating a Chinese Provincial Public Security Bureau app, revealing 170 active servers running the framework. Two Telegram channels distribute modified versions with operational support and cash-out services charging 20-50% fees. The platform integrates APK generation, command and control device management, and phishing overlays targeting financial, adult, and government sectors. In June 2026, a successor platform named Night Dragon was launched, featuring improved credential capture for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity mainly targets Chinese citizens via social engineering, though international targeting capabilities exist.
Potential Impact
The threat enables credential theft and remote access on Android devices, facilitating financial fraud, identity theft, and unauthorized access to sensitive accounts. The stolen source code and customer databases have led to widespread distribution and modification of the malware, increasing its operational scale. The introduction of Night Dragon with enhanced credential capture capabilities raises the risk of more effective theft from banking and cryptocurrency applications. The use of phishing overlays and impersonation of official apps increases the likelihood of successful social engineering attacks against victims.
Defensive Guidance
No official patch or remediation is available as this is a malware threat rather than a software vulnerability. Defenders should focus on detecting and blocking malicious APKs, monitoring for indicators of compromise related to Flying Eagle and Night Dragon, and educating users about phishing and social engineering risks. Network defenders should monitor for communications with known command and control servers associated with this malware. Since the source code is leaked and the malware is actively distributed, proactive threat hunting and endpoint protection are recommended.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon"]
- Pulse Id
- 6a691cbdc292b7f2437d3655
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain110gongan.com | — | |
domainfusu666.cc | — | |
domainxyttkx.cc | — | |
domainalcs.xyttkx.cc | — | |
domainh5.xyttkx.cc | — | |
domainls.j2x8a.top | — | |
domains.orove.cn | — | |
domaintxl.xyttkx.cc | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash18827998ad05c58da1d218066374fe16 | — | |
hash645ee92d197441684919c0b1ad5cfd15 | — | |
hash81694f8296ea8e589acc68382add4311 | — | |
hashb5f64311ffe3c6f1eb13b769663702c6 | — | |
hashd23e2d0c71cbf0a5d67e17e7b3c690e0 | — | |
hash5d95ddf7cd857acaaa3447e710a3ee596262b4e2 | — | |
hash68389a8ae359c2e730e33ab60e9fa6ad71120983 | — | |
hashd767524b3b288f09840f3d7196718e4187515f6b | — | |
hashe02955f78fca6c758d760c36474ae0d4f546efb4 | — | |
hashe9c71b51de94d6ef1f1090a36754d987374f6f70 | — | |
hash0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f | — | |
hash1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a | — | |
hash4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 | — | |
hash5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b | — | |
hash773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df | — | |
hash7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af | — | |
hash82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 | — | |
hashb803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 | — | |
hashc692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd | — | |
hashd8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip108.187.7.66 | — | |
ip108.187.7.71 | — | |
ip154.44.25.12 | — | |
ip207.56.30.188 | — | |
ip207.56.30.194 | — | |
ip77.105.161.235 | — | |
ip85.137.253.48 | — |
Threat ID: 6a69eceb9c2644c7f878acba
Added to database: 07/29/2026, 12:07:07 UTC
Last enriched: 08/06/2026, 12:42:41 UTC
Last updated: 09/10/2026, 22:45:01 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.