Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.
AI Analysis
Technical Summary
The Flying Eagle Android RAT source code leak in early 2026 enabled widespread malicious activity, including nearly 200 stolen customer databases and 170 active command-and-control servers. Distribution occurs through malicious APKs masquerading as official Chinese Provincial Public Security Bureau apps. Two Telegram channels, SQLRCE0 and Yx Technology, facilitate distribution of modified RAT versions and provide operational support and cash-out services with transaction fees. The platform integrates APK generation, C2 device management, and phishing overlays targeting financial, adult, and government services. In June 2026, a new platform called Night Dragon was launched, improving credential capture for Chinese banking applications, cryptocurrency wallets, and social media platforms. While the primary focus is on Chinese citizens, the presence of international phishing templates indicates potential for wider targeting.
Potential Impact
The leak of Flying Eagle's source code and associated customer databases has enabled a fragmented criminal ecosystem with numerous active servers facilitating Android RAT operations. This results in credential theft, financial fraud, and espionage against targeted users, mainly Chinese citizens. The introduction of Night Dragon increases the threat by enhancing credential capture capabilities for high-value targets such as banking and cryptocurrency applications. The availability of operational support and cash-out services lowers the barrier for threat actors to monetize stolen credentials and conduct fraud.
Mitigation Recommendations
No official patch or remediation is available since this is malware and not a software vulnerability. Defenders should focus on detecting and blocking malicious APKs impersonating legitimate apps, monitoring for network traffic to known command-and-control servers, and educating users about social engineering lures. Since the threat actors use Telegram channels for distribution and support, monitoring these channels may provide early warning. There is no vendor-managed remediation as this is not a cloud service. Patch status is not applicable.
Affected Countries
China
Indicators of Compromise
- domain: 110gongan.com
- hash: 18827998ad05c58da1d218066374fe16
- hash: 645ee92d197441684919c0b1ad5cfd15
- hash: 81694f8296ea8e589acc68382add4311
- hash: b5f64311ffe3c6f1eb13b769663702c6
- hash: d23e2d0c71cbf0a5d67e17e7b3c690e0
- hash: 5d95ddf7cd857acaaa3447e710a3ee596262b4e2
- hash: 68389a8ae359c2e730e33ab60e9fa6ad71120983
- hash: d767524b3b288f09840f3d7196718e4187515f6b
- hash: e02955f78fca6c758d760c36474ae0d4f546efb4
- hash: e9c71b51de94d6ef1f1090a36754d987374f6f70
- hash: 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f
- hash: 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a
- hash: 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164
- hash: 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b
- hash: 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df
- hash: 7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af
- hash: 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7
- hash: b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3
- hash: c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd
- hash: d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e
- ip: 108.187.7.66
- ip: 108.187.7.71
- ip: 154.44.25.12
- ip: 207.56.30.188
- ip: 207.56.30.194
- ip: 77.105.161.235
- ip: 85.137.253.48
- domain: fusu666.cc
- domain: xyttkx.cc
- domain: alcs.xyttkx.cc
- domain: h5.xyttkx.cc
- domain: ls.j2x8a.top
- domain: s.orove.cn
- domain: txl.xyttkx.cc
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Description
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Flying Eagle Android RAT source code leak in early 2026 enabled widespread malicious activity, including nearly 200 stolen customer databases and 170 active command-and-control servers. Distribution occurs through malicious APKs masquerading as official Chinese Provincial Public Security Bureau apps. Two Telegram channels, SQLRCE0 and Yx Technology, facilitate distribution of modified RAT versions and provide operational support and cash-out services with transaction fees. The platform integrates APK generation, C2 device management, and phishing overlays targeting financial, adult, and government services. In June 2026, a new platform called Night Dragon was launched, improving credential capture for Chinese banking applications, cryptocurrency wallets, and social media platforms. While the primary focus is on Chinese citizens, the presence of international phishing templates indicates potential for wider targeting.
Potential Impact
The leak of Flying Eagle's source code and associated customer databases has enabled a fragmented criminal ecosystem with numerous active servers facilitating Android RAT operations. This results in credential theft, financial fraud, and espionage against targeted users, mainly Chinese citizens. The introduction of Night Dragon increases the threat by enhancing credential capture capabilities for high-value targets such as banking and cryptocurrency applications. The availability of operational support and cash-out services lowers the barrier for threat actors to monetize stolen credentials and conduct fraud.
Mitigation Recommendations
No official patch or remediation is available since this is malware and not a software vulnerability. Defenders should focus on detecting and blocking malicious APKs impersonating legitimate apps, monitoring for network traffic to known command-and-control servers, and educating users about social engineering lures. Since the threat actors use Telegram channels for distribution and support, monitoring these channels may provide early warning. There is no vendor-managed remediation as this is not a cloud service. Patch status is not applicable.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon"]
- Adversary
- null
- Pulse Id
- 6a691cbdc292b7f2437d3655
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain110gongan.com | — | |
domainfusu666.cc | — | |
domainxyttkx.cc | — | |
domainalcs.xyttkx.cc | — | |
domainh5.xyttkx.cc | — | |
domainls.j2x8a.top | — | |
domains.orove.cn | — | |
domaintxl.xyttkx.cc | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash18827998ad05c58da1d218066374fe16 | — | |
hash645ee92d197441684919c0b1ad5cfd15 | — | |
hash81694f8296ea8e589acc68382add4311 | — | |
hashb5f64311ffe3c6f1eb13b769663702c6 | — | |
hashd23e2d0c71cbf0a5d67e17e7b3c690e0 | — | |
hash5d95ddf7cd857acaaa3447e710a3ee596262b4e2 | — | |
hash68389a8ae359c2e730e33ab60e9fa6ad71120983 | — | |
hashd767524b3b288f09840f3d7196718e4187515f6b | — | |
hashe02955f78fca6c758d760c36474ae0d4f546efb4 | — | |
hashe9c71b51de94d6ef1f1090a36754d987374f6f70 | — | |
hash0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f | — | |
hash1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a | — | |
hash4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 | — | |
hash5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b | — | |
hash773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df | — | |
hash7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af | — | |
hash82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 | — | |
hashb803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 | — | |
hashc692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd | — | |
hashd8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip108.187.7.66 | — | |
ip108.187.7.71 | — | |
ip154.44.25.12 | — | |
ip207.56.30.188 | — | |
ip207.56.30.194 | — | |
ip77.105.161.235 | — | |
ip85.137.253.48 | — |
Threat ID: 6a69eceb9c2644c7f878acba
Added to database: 07/29/2026, 12:07:07 UTC
Last enriched: 07/29/2026, 14:14:35 UTC
Last updated: 07/30/2026, 02:08:04 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.