Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

0
Medium
Published: 07/28/2026 (07/28/2026, 21:18:53 UTC)
Source: AlienVault OTX General

Description

Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 14:14:35 UTC

Technical Analysis

The Flying Eagle Android RAT source code leak in early 2026 enabled widespread malicious activity, including nearly 200 stolen customer databases and 170 active command-and-control servers. Distribution occurs through malicious APKs masquerading as official Chinese Provincial Public Security Bureau apps. Two Telegram channels, SQLRCE0 and Yx Technology, facilitate distribution of modified RAT versions and provide operational support and cash-out services with transaction fees. The platform integrates APK generation, C2 device management, and phishing overlays targeting financial, adult, and government services. In June 2026, a new platform called Night Dragon was launched, improving credential capture for Chinese banking applications, cryptocurrency wallets, and social media platforms. While the primary focus is on Chinese citizens, the presence of international phishing templates indicates potential for wider targeting.

Potential Impact

The leak of Flying Eagle's source code and associated customer databases has enabled a fragmented criminal ecosystem with numerous active servers facilitating Android RAT operations. This results in credential theft, financial fraud, and espionage against targeted users, mainly Chinese citizens. The introduction of Night Dragon increases the threat by enhancing credential capture capabilities for high-value targets such as banking and cryptocurrency applications. The availability of operational support and cash-out services lowers the barrier for threat actors to monetize stolen credentials and conduct fraud.

Mitigation Recommendations

No official patch or remediation is available since this is malware and not a software vulnerability. Defenders should focus on detecting and blocking malicious APKs impersonating legitimate apps, monitoring for network traffic to known command-and-control servers, and educating users about social engineering lures. Since the threat actors use Telegram channels for distribution and support, monitoring these channels may provide early warning. There is no vendor-managed remediation as this is not a cloud service. Patch status is not applicable.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon"]
Adversary
null
Pulse Id
6a691cbdc292b7f2437d3655
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domain110gongan.com
domainfusu666.cc
domainxyttkx.cc
domainalcs.xyttkx.cc
domainh5.xyttkx.cc
domainls.j2x8a.top
domains.orove.cn
domaintxl.xyttkx.cc

Hash

ValueDescriptionCopy
hash18827998ad05c58da1d218066374fe16
hash645ee92d197441684919c0b1ad5cfd15
hash81694f8296ea8e589acc68382add4311
hashb5f64311ffe3c6f1eb13b769663702c6
hashd23e2d0c71cbf0a5d67e17e7b3c690e0
hash5d95ddf7cd857acaaa3447e710a3ee596262b4e2
hash68389a8ae359c2e730e33ab60e9fa6ad71120983
hashd767524b3b288f09840f3d7196718e4187515f6b
hashe02955f78fca6c758d760c36474ae0d4f546efb4
hashe9c71b51de94d6ef1f1090a36754d987374f6f70
hash0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f
hash1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a
hash4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164
hash5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b
hash773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df
hash7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af
hash82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7
hashb803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3
hashc692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd
hashd8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e

Ip

ValueDescriptionCopy
ip108.187.7.66
ip108.187.7.71
ip154.44.25.12
ip207.56.30.188
ip207.56.30.194
ip77.105.161.235
ip85.137.253.48

Threat ID: 6a69eceb9c2644c7f878acba

Added to database: 07/29/2026, 12:07:07 UTC

Last enriched: 07/29/2026, 14:14:35 UTC

Last updated: 07/30/2026, 02:08:04 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses