MEDIUMMalware
Global

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

·Source: The Hacker News

Updated:

Executive Summary

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password

Analysis

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password

Indicators of Compromise (1)

Domain (1)
Source Attribution

Originally published by The Hacker News on Jul 29, 2026.

Related Threats