# Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges

> Leaked source code for the Flying Eagle (飞鹰) Android RAT/APK-builder framework circulated via Telegram in 2026, letting researchers at Hunt.io and independent analyst NetAskari fingerprint 170 live command-and-control servers (158 AdminPro panels + 12 shared-certificate systems), most hosted in Hong Kong. The framework builds trojanized APKs with phishing overlays for Alipay, WeChat, and Chinese banks, and the same leak actor (SQLRCE0) launched a successor platform, Night Dragon (夜龙), on June 23, 2026, already advancing to a v2 build by July 12, 2026.

- **Published:** 2026-07-29T00:00:00Z
- **Last reviewed:** 2026-07-30T03:32:04.230Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1757
- **ID:** TL-2026-1757
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Flying Eagle Tech
- **Detections:** 9 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Flying Eagle (飞鹰) is a full-stack Android device-management and APK-building framework: a PHP/MySQL/nginx C2 backend (branded "AdminPro" or "SQLRCE"), a Node.js WebSocket channel for live device control, and an APK builder that stamps operator-supplied branding, package names, and C2 endpoints onto a stock trojan payload. The framework's source was compromised in early 2026 — leak chat logs show an unknown party negotiating access to roughly 189-200 customer databases belonging to the original "飞鹰技术" (Flying Eagle Tech) developer group. The stolen code, packaged as a 388 MB Docker archive (中国龙.zip, "Chinese Dragon") and a 292 MB XAMPP archive (飞鹰控打包.zip), was redistributed from two Telegram channels: @SQLRCE0 (created 2026-02-04), which sold a "fixed" build for 2,000 USDT and later introduced Night Dragon, and Yx科技/Yx Technology (created 2026-04-08), which bundled Flying Eagle with the related BTMOB RAT and offered fraud cash-out services at 20-50% transaction fees.

Hunt.io and NetAskari fingerprinted the AdminPro/SQLRCE HTML titles, the shared HTTP redirect behavior (302 to HTTPS with a hard-coded Strict-Transport-Security header), and a default packaged TLS certificate (subject CN alcs.xyttkx.cc, Let's Encrypt R13, valid 2026-04-07 to 2026-07-06) to pivot across infrastructure and identify 170 servers total: 158 unique AdminPro-branded panels, 57 SQLRCE-titled panels, and 12 systems sharing the default certificate, concentrated on Hong Kong ASNs (Antbox Networks, Cognetcloud, CTG Server Limited, Zillion Network) with additional nodes in the United States, mainland China, Finland, Malaysia, Canada, and Japan. A March 13, 2026 open directory at 77.105.161[.]235:8000 (2,383 files, 1.4 GB) exposed builder tooling, an AnyDesk license tied to a Hong Kong host, and a PHP-CGI exploit reference on a separate German-hosted node, illustrating operational sloppiness across the criminal supply chain.

Operationally, Flying Eagle's APK builder (ApkBuilder.php) randomizes the hard-coded default package name (com.icontrol.protector) into legitimate-sounding identifiers, renames internal classes to 8-14 character random strings, pads the APK with 2.8-3.5 MB of fake JSON "SDK configuration cache" files to lower entropy and evade static AV heuristics (a developer comment explicitly notes this goal), and encrypts the embedded C2 URL with AES-128-CBC using a hard-coded default IV, password, and PBKDF2-SHA1 (65,536 iterations) key derivation — meaning every unmodified build shares the same effective encryption secret. Once installed via social-engineering lures (fake Public Security Bureau apps such as autoclicker_pro.apk served from 110gongan[.]com, adult-content and streaming apps, TikTok/financial-app clones, and "public welfare" landing pages), the payload abuses Android's Accessibility Service (AccessibilityActivity module) to capture keystrokes (LiveKeysStrok), take screenshots (ScreenCaps), access the camera (CameraCap), record audio, inject phishing overlays over banking/payment apps to steal credentials (RecordPayPassword, Webjector) targeting Alipay, WeChat, ICBC, China Construction Bank, Agricultural Bank of China, TokenPocket, and imToken, and grant the operator live screen viewing, SMS/photo access, and file management from the AdminPro panel.

The successor platform Night Dragon (夜龙), introduced by @SQLRCE0 on 2026-06-23 and already in v2 development by 2026-07-12, adds a black-screen mode that displays a fake system-update screen to mask attacker activity, icon-hiding after installation, and the same payment-credential-capture focus; its console (夜龙控制台) showed 46 enrolled devices (29 actively connected, all in China) at analysis time on two dedicated Zillion Network (AS54801) servers. Chinese state media (CCTV) issued a public consumer-safety notice on 2026-06-18 warning citizens about fraudulent PSB-impersonating apps, corroborating active real-world victimization ahead of the technical disclosure. The Yx科技 channel separately distributes the related BTMOB RAT (v4.5.5, password-protected) and a standalone builder branded "GitHub V1.2" (unrelated to the code-hosting platform), indicating a shared criminal tooling ecosystem feeding multiple Android RAT families into the same Chinese-fraud target set.

## MITRE ATT&CK

- T1660 Phishing
- T1655 Masquerading
- T1629 Impair Defenses
- T1541 Foreground Persistence
- T1626 Abuse Elevation Control Mechanism
- T1453 Abuse Accessibility Features
- T1628 Hide Artifacts
- T1630 Indicator Removal on Host
- T1406 Obfuscated Files or Information
- T1407 Download New Code at Runtime
- T1417 Input Capture
- T1634 Credentials from Password Store
- T1513 Screen Capture
- T1512 Video Capture
- T1429 Audio Capture
- T1636 Protected User Data
- T1437 Application Layer Protocol
- T1521 Encrypted Channel
- T1646 Exfiltration Over C2 Channel
- T1516 Input Injection
- T1624 Event Triggered Execution
- T1430 Location Tracking
- T1533 Data from Local System

## Sources

- [Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon](https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon)
- [Malpedia library entry: Flying Eagle Android RAT](https://malpedia.caad.fkie.fraunhofer.de/library/272bb79a-dcd5-4298-8d94-a358ba9d7e2a/)
- [Complete IOC list — Flying Eagle / Night Dragon](https://hunt.io/files/flying_eagle_iocs.txt)
- [Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates](https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html)
- [A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online](https://cybersecuritynews.com/a-leaked-android-rat/)
- [Flying Eagle Android RAT: Traces on 170 Servers](https://www.secnews.gr/en/724489/flying-eagle-android-rat-170-servers/)
- [Flying Eagle RAT (Android) - Malware removal instructions](https://www.pcrisk.com/removal-guides/35656-flying-eagle-rat-android)
- [A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online | Cryptika Cybersecurity](https://www.cryptika.com/a-leaked-android-rat-is-powering-170-servers-and-its-successor-is-already-online/)
- [SpyNote: Advanced Android Spyware and RAT Threat](https://hunt.io/malware-families/spynote)
- [BTMOB: A stealthy RAT burrowing deep into Android devices](https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/)
- [BTMOB RAT (Malware Family)](https://malpedia.caad.fkie.fraunhofer.de/details/apk.btmob)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1757
