Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges — Threadlinqs Intelligence
As of 2026-07-30, Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges is a high-severity malware threat attributed to Flying Eagle Tech, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-1757 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-30 · revalidated 1× · latest source
Attribution: Flying Eagle Tech · FINANCIAL
Leaked source code for the Flying Eagle (飞鹰) Android RAT/APK-builder framework circulated via Telegram in 2026, letting researchers at Hunt.io and independent analyst NetAskari fingerprint 170 live
Flying Eagle (飞鹰) is a full-stack Android device-management and APK-building framework: a PHP/MySQL/nginx C2 backend (branded "AdminPro" or "SQLRCE"), a Node.js WebSocket channel for live device control, and an APK builder that stamps operator-supplied branding, package names, and C2 endpoints onto a stock trojan payload. The framework's source was compromised in early 2026 — leak chat logs show an unknown party negotiating access to roughly 189-200 customer databases belonging to the original "飞鹰技术" (Flying Eagle Tech) developer group. The stolen code, packaged as a 388 MB Docker archive (中国龙.zip, "Chinese Dragon") and a 292 MB XAMPP archive (飞鹰控打包.zip), was redistributed from two Telegram channels: @SQLRCE0 (created 2026-02-04), which sold a "fixed" build for 2,000 USDT and later introduced Night Dragon, and Yx科技/Yx Technology (created 2026-04-08), which bundled Flying Eagle with the related BTMOB RAT and offered fraud cash-out services at 20-50% transaction fees.
Hunt.io and NetAskari fingerprinted the AdminPro/SQLRCE HTML titles, the shared HTTP redirect behavior (302 to HTTPS with a hard-coded Strict-Transport-Security header), and a default packaged TLS certificate (subject CN alcs.xyttkx.cc, Let's Encrypt R13, valid 2026-04-07 to 2026-07-06) to pivot across infrastructure and identify 170 servers total: 158 unique AdminPro-branded panels, 57 SQLRCE-titled panels, and 12 systems sharing the default certificate, concentrated on Hong Kong ASNs (Antbox Networks, Cognetcloud, CTG Server Limited, Zillion Network) with additional nodes in the United States, mainland China, Finland, Malaysia, Canada, and Japan. A March 13, 2026 open directory at 77.105.161[.]235:8000 (2,383 files, 1.4 GB) exposed builder tooling, an AnyDesk license tied to a Hong Kong host, and a PHP-CGI exploit reference on a separate German-hosted node, illustrating operational sloppiness across the criminal supply chain.
Operationally, Flying Eagle's APK builder (ApkBuilder.php) randomizes the hard-coded default package name (com.icontrol.protector) into legitimate-sounding identifiers, renames internal classes to 8-14 character random strings, pads the APK with 2.8-3.5 MB of fake JSON "SDK configuration cache" files to lower entropy and evade static AV heuristics (a developer comment explicitly notes this goal), and encrypts the embedded C2 URL with AES-128-CBC using a hard-coded default IV, password, and PBKDF2-SHA1 (65,536 iterations) key derivation — meaning every unmodified build shares the same effective encryption secret. Once installed via social-engineering lures (fake Public Security Bureau apps such as autoclicker_pro.apk served from 110gongan[.]com, adult-content and streaming apps, TikTok/financial-app clones, and "public welfare" landing pages), the payload abuses Android's Accessibility Service (AccessibilityActivity module) to capture keystrokes (LiveKeysStrok), take screenshots (ScreenCaps), access the camera (CameraCap), record audio, inject phishing overlays over banking/payment apps to steal credentials (RecordPayPassword, Webjector) targeting Alipay, WeChat, ICBC, China Construction Bank, Agricultural Bank of China, TokenPocket, and imToken, and grant the operator live screen viewing, SMS/photo access, and file management from the AdminPro panel.
The successor platform Night Dragon (夜龙), introduced by @SQLRCE0 on 2026-06-23 and already in v2 development by 2026-07-12, adds a black-screen mode that displays a fake system-update screen to mask attacker activity, icon-hiding after installation, and the same payment-credential-capture focus; its console (夜龙控制台) showed 46 enrolled devices (29 actively connected, all in China) at analysis time on two dedicated Zillion Network (AS54801) servers. Chinese state media (CCTV) issued a public consumer-safety notice on 2026-06-18 warning citizens about fraudulent PSB-impersonating apps, corroborating active real-world victimization ahead of the technical disclosure. The Yx科技 channel separately dis
Weaknesses (CWE)
CWE-798, CWE-250, CWE-269, CWE-451
Target sectors: consumer, finance, government administration, cryptocurrency
Target regions: china, hong kong
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1655, T1629, T1541, T1626, T1453, T1628, T1630, T1406, T1407