Skip to main content

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

0
Medium
Published: 07/28/2026 (07/28/2026, 21:18:53 UTC)
Source: AlienVault OTX General

Description

Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 12:42:41 UTC

Technical Analysis

Researchers uncovered a criminal ecosystem built around Flying Eagle, an Android RAT whose source code and customer databases were stolen in early 2026. The investigation started from a malicious APK impersonating a Chinese Provincial Public Security Bureau app, revealing 170 active servers running the framework. Two Telegram channels distribute modified versions with operational support and cash-out services charging 20-50% fees. The platform integrates APK generation, command and control device management, and phishing overlays targeting financial, adult, and government sectors. In June 2026, a successor platform named Night Dragon was launched, featuring improved credential capture for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity mainly targets Chinese citizens via social engineering, though international targeting capabilities exist.

Potential Impact

The threat enables credential theft and remote access on Android devices, facilitating financial fraud, identity theft, and unauthorized access to sensitive accounts. The stolen source code and customer databases have led to widespread distribution and modification of the malware, increasing its operational scale. The introduction of Night Dragon with enhanced credential capture capabilities raises the risk of more effective theft from banking and cryptocurrency applications. The use of phishing overlays and impersonation of official apps increases the likelihood of successful social engineering attacks against victims.

Defensive Guidance

No official patch or remediation is available as this is a malware threat rather than a software vulnerability. Defenders should focus on detecting and blocking malicious APKs, monitoring for indicators of compromise related to Flying Eagle and Night Dragon, and educating users about phishing and social engineering risks. Network defenders should monitor for communications with known command and control servers associated with this malware. Since the source code is leaked and the malware is actively distributed, proactive threat hunting and endpoint protection are recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon"]
Pulse Id
6a691cbdc292b7f2437d3655

Indicators of Compromise

Domain

ValueDescriptionCopy
domain110gongan.com
domainfusu666.cc
domainxyttkx.cc
domainalcs.xyttkx.cc
domainh5.xyttkx.cc
domainls.j2x8a.top
domains.orove.cn
domaintxl.xyttkx.cc

Hash

ValueDescriptionCopy
hash18827998ad05c58da1d218066374fe16
hash645ee92d197441684919c0b1ad5cfd15
hash81694f8296ea8e589acc68382add4311
hashb5f64311ffe3c6f1eb13b769663702c6
hashd23e2d0c71cbf0a5d67e17e7b3c690e0
hash5d95ddf7cd857acaaa3447e710a3ee596262b4e2
hash68389a8ae359c2e730e33ab60e9fa6ad71120983
hashd767524b3b288f09840f3d7196718e4187515f6b
hashe02955f78fca6c758d760c36474ae0d4f546efb4
hashe9c71b51de94d6ef1f1090a36754d987374f6f70
hash0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f
hash1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a
hash4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164
hash5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b
hash773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df
hash7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af
hash82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7
hashb803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3
hashc692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd
hashd8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e

Ip

ValueDescriptionCopy
ip108.187.7.66
ip108.187.7.71
ip154.44.25.12
ip207.56.30.188
ip207.56.30.194
ip77.105.161.235
ip85.137.253.48

Threat ID: 6a69eceb9c2644c7f878acba

Added to database: 07/29/2026, 12:07:07 UTC

Last enriched: 08/06/2026, 12:42:41 UTC

Last updated: 09/10/2026, 22:45:01 UTC

Views: 188

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses