Threat reportMalwareTL-2026-1757

Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges

highACTIVE

Flying Eagle Android RAT (TL-2026-1757), also tracked as Flying Eagle, is a high-severity malware campaign, first published 2026-07-29 and last reviewed 2026-07-30. It is attributed to Flying Eagle Tech with medium confidence, affects Google Android OS (sideloaded third-party APKs), maps to 23 MITRE ATT&CK techniques (T1406, T1407, T1417), and is covered by 9 detection rules and 38 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1Flying Eagle Tech
Detection rules
9SPL · KQL · Sigma
IOCs
38Indicators of compromise

Key facts for TL-2026-1757

Threat ID
TL-2026-1757
Also known as
Flying Eagle, 飞鹰, Night Dragon, 夜龙, Feiying
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Flying Eagle Tech
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
consumer, finance, government administration, cryptocurrency
Target regions
china, hong kong
Detection rules
9
Indicators of compromise
38
Updates
2026-07-30 · revalidated 1× · latest source

Malware and tooling in Flying Eagle Android RAT

Malware and tooling: BTMOB RAT, Flying Eagle (飞鹰), Night Dragon (夜龙), AdminPro panel, SQLRCE panel

How Flying Eagle Android RAT works

Leaked source code for the Flying Eagle (飞鹰) Android RAT/APK-builder framework circulated via Telegram in 2026, letting researchers at Hunt.io and independent analyst NetAskari fingerprint 170 live command-and-control servers (158 AdminPro panels + 12 shared-certificate systems), most hosted in Hong Kong. The framework builds trojanized APKs with phishing overlays for Alipay, WeChat, and Chinese banks, and the same leak actor (SQLRCE0) launched a successor platform, Night Dragon (夜龙), on June 23, 2026, already advancing to a v2 build by July 12, 2026.

Flying Eagle (飞鹰) is a full-stack Android device-management and APK-building framework: a PHP/MySQL/nginx C2 backend (branded "AdminPro" or "SQLRCE"), a Node.js WebSocket channel for live device control, and an APK builder that stamps operator-supplied branding, package names, and C2 endpoints onto a stock trojan payload. The framework's source was compromised in early 2026 — leak chat logs show an unknown party negotiating access to roughly 189-200 customer databases belonging to the original "飞鹰技术" (Flying Eagle Tech) developer group. The stolen code, packaged as a 388 MB Docker archive (中国龙.zip, "Chinese Dragon") and a 292 MB XAMPP archive (飞鹰控打包.zip), was redistributed from two Telegram channels: @SQLRCE0 (created 2026-02-04), which sold a "fixed" build for 2,000 USDT and later introduced Night Dragon, and Yx科技/Yx Technology (created 2026-04-08), which bundled Flying Eagle with the related BTMOB RAT and offered fraud cash-out services at 20-50% transaction fees.

Hunt.io and NetAskari fingerprinted the AdminPro/SQLRCE HTML titles, the shared HTTP redirect behavior (302 to HTTPS with a hard-coded Strict-Transport-Security header), and a default packaged TLS certificate (subject CN alcs.xyttkx.cc, Let's Encrypt R13, valid 2026-04-07 to 2026-07-06) to pivot across infrastructure and identify 170 servers total: 158 unique AdminPro-branded panels, 57 SQLRCE-titled panels, and 12 systems sharing the default certificate, concentrated on Hong Kong ASNs (Antbox Networks, Cognetcloud, CTG Server Limited, Zillion Network) with additional nodes in the United States, mainland China, Finland, Malaysia, Canada, and Japan. A March 13, 2026 open directory at 77.105.161[.]235:8000 (2,383 files, 1.4 GB) exposed builder tooling, an AnyDesk license tied to a Hong Kong host, and a PHP-CGI exploit reference on a separate German-hosted node, illustrating operational sloppiness across the criminal supply chain.

Operationally, Flying Eagle's APK builder (ApkBuilder.php) randomizes the hard-coded default package name (com.icontrol.protector) into legitimate-sounding identifiers, renames internal classes to 8-14 character random strings, pads the APK with 2.8-3.5 MB of fake JSON "SDK configuration cache" files to lower entropy and evade static AV heuristics (a developer comment explicitly notes this goal), and encrypts the embedded C2 URL with AES-128-CBC using a hard-coded default IV, password, and PBKDF2-SHA1 (65,536 iterations) key derivation — meaning every unmodified build shares the same effective encryption secret. Once installed via social-engineering lures (fake Public Security Bureau apps such as autoclicker_pro.apk served from 110gongan[.]com, adult-content and streaming apps, TikTok/financial-app clones, and "public welfare" landing pages), the payload abuses Android's Accessibility Service (AccessibilityActivity module) to capture keystrokes (LiveKeysStrok), take screenshots (ScreenCaps), access the camera (CameraCap), record audio, inject phishing overlays over banking/payment apps to steal credentials (RecordPayPassword, Webjector) targeting Alipay, WeChat, ICBC, China Construction Bank, Agricultural Bank of China, TokenPocket, and imToken, and grant the operator live screen viewing, SMS/photo access, and file management from the AdminPro panel.

The successor platform Night Dragon (夜龙), introduced by @SQLRCE0 on 2026-06-23 and already in v2 development by 2026-07-12, adds a black-screen mode that displays a fake system-update screen to mask attacker activity, icon-hiding after installation, and the same payment-credential-capture focus; its console (夜龙控制台) showed 46 enrolled devices (29 actively connected, all in China) at analysis time on two dedicated Zillion Network (AS54801) servers. Chinese state media (CCTV) issued a public consumer-safety notice on 2026-06-18 warning citizens about fraudulent PSB-impersonating apps, corroborating active real-world victimization ahead of the technical disclosure. The Yx科技 channel separately distributes the related BTMOB RAT (v4.5.5, password-protected) and a standalone builder branded "GitHub V1.2" (unrelated to the code-hosting platform), indicating a shared criminal tooling ecosystem feeding multiple Android RAT families into the same Chinese-fraud target set.

MITRE ATT&CK techniques used in TL-2026-1757

Defense Evasion

T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1516 Input Injection; T1628 Hide Artifacts; T1630 Indicator Removal on Host; T1655 Masquerading

Credential Access

T1417 Input Capture; T1453 Abuse Accessibility Features; T1634 Credentials from Password Store

Collection

T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1513 Screen Capture; T1533 Data from Local System; T1636 Protected User Data

Command and Control

T1437 Application Layer Protocol; T1521 Encrypted Channel

Persistence

T1541 Foreground Persistence; T1624 Event Triggered Execution

Privilege Escalation

T1626 Abuse Elevation Control Mechanism

defense-evasion

T1629 Impair Defenses

Exfiltration

T1646 Exfiltration Over C2 Channel

Initial Access

T1660 Phishing

Affected products and versions in Flying Eagle Android RAT

  • Google — Android OS (sideloaded third-party APKs)
    Vulnerable versions: All actively supported Android versions permitting Accessibility Service grants and sideloaded APK installation

Remediation for Flying Eagle Android RAT

Immediate actions

  • Block installation of APKs from unofficial/sideloaded sources; disable 'install unknown apps' permission where not operationally required
  • Block network egress to all identified Flying Eagle / Night Dragon C2 IPs and domains at DNS resolver, firewall, and proxy layers
  • Audit installed apps on managed/BYOD Android devices for Accessibility Service grants and revoke access from any app not explicitly required to hold it
  • Warn users about phishing lures impersonating Public Security Bureau apps, government-service apps, banking/payment apps, and adult-content platforms distributed via Telegram, SMS, and lookalike landing pages

Workarounds

  • Disable installation from unknown sources (sideloading) via Android/MDM enterprise policy
  • Restrict Accessibility Service permission grants via MDM on corporate-managed devices

Longer-term hardening

  • Deploy mobile threat defense (MTD) / EDR on managed Android fleets with behavioral detection for Accessibility-Service abuse, overlay injection, and screen/keystroke/camera capture
  • Build C2 panel fingerprinting (HTML title 'AdminPro'/'SQLRCE'/夜龙控制台, HSTS header on 302 redirect, /login?redirect= route pattern) into network detection content
  • Monitor Certificate Transparency logs for newly issued Let's Encrypt certificates on lookalike domains resembling banking, government, or platform-relevant brands
  • Maintain continuous IOC ingestion from Hunt.io/Malpedia/NetAskari reporting given the framework's rapid, low-cost infrastructure rotation

Weaknesses (CWE) in Flying Eagle Android RAT

CWE-798, CWE-250, CWE-269, CWE-451

Timeline of Flying Eagle Android RAT

  • @SQLRCE0 Telegram channel created; first post distributes 飞鹰控打包.zip (XAMPP-based Flying Eagle package)
  • SQLRCE0 posts chat logs referencing the Flying Eagle source code compromise and announces a 'fixed' build for sale at 2,000 USDT
  • SQLRCE0 continues distributing source code upgrades to the Flying Eagle builder (through 2026-03-09)
  • First observation of an open directory at 77.105.161[.]235:8000 (2,383 files, 1.4 GB) exposing builder tooling and an AnyDesk license
  • Yx科技 (Yx Technology) Telegram channel created, publishing fraud/cash-out instructions and reselling Flying Eagle
  • Yx科技 distributes 中国龙.zip, a 388 MB Docker-based deployment of the Flying Eagle framework
  • Yx科技 uploads a password-protected copy of BTMOB RAT v4.5.5
  • Yx科技 begins offering phishing landing pages bundled with an admin backend and visitor-metrics dashboard
  • TLS certificate issued for C2 domain ls.j2x8a[.]top, later used to pivot to additional Flying Eagle infrastructure
  • Chinese state media (CCTV) publishes a public consumer-safety notice warning citizens about fraudulent apps impersonating the Public Security Bureau
  • SQLRCE0 introduces the Night Dragon (夜龙) successor platform
  • Night Dragon version 2 observed in active development
  • Hunt.io and Malpedia publish research fingerprinting 170 active Flying Eagle/Night Dragon C2 servers and full IOC set
  • The Hacker News and other outlets (GBHackers, Cybersecurity News, SecNews.gr) publish coverage summarizing the Hunt.io/NetAskari findings, bringing the campaign to broad public and defender awareness.

Update history for TL-2026-1757

Sources cited for Flying Eagle Android RAT

Detection coverage for TL-2026-1757

As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1757 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
38 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1757

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats