CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3414

As cited

Copy frozen at (site build).

threat intel

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating in criminal Telegram channels, with researchers tracing its control panels and certificates to 170 internet servers. The framework is deployed through a fake Chinese public security application and supports credential theft functionality. Widespread distribution of the malware kit indicates potential for rapid proliferation among threat actors.

Why it matters: Mobile security teams and organizations with Android users in China face heightened risk from this leaked RAT framework, which could enable attackers to conduct remote surveillance and credential harvesting at scale.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, with researchers identifying 170 servers hosting matching control panels and certificates. The framework was distributed through a spoofed Chinese Public Security service application and supports payment-password harvesting functionality.

Why it matters: Organizations with users in China and mobile security teams should monitor for Flying Eagle variants; the availability of source code increases the likelihood of derivative malware and attack variations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, with researchers identifying 170 servers hosting matching control panels and certificates. The framework was distributed through a spoofed Chinese Public Security service application and supports payment-password harvesting functionality.

Why it matters: Organizations with users in China and mobile security teams should monitor for Flying Eagle variants; the availability of source code increases the likelihood of derivative malware and attack variations.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary