Researchers have mapped a large Android remote access trojan (RAT) operation linked to Flying Eagle (飞鹰), a leaked malware framework used to build malicious Android apps and manage infected devices.
The platform was identified across 170 servers after investigators traced a fake Chinese Public Security Bureau application to shared infrastructure, TLS certificates, panel fingerprints, and Telegram-based malware distribution.
The activity appears financially motivated and primarily targets Chinese Android users with fraudulent government-service, financial, adult-content, and social-media lures.
A newer Android RAT platform named Night Dragon (夜龙), promoted by an actor using the SQLRCE0 Telegram account, may represent the next stage of this malware ecosystem
Flying Eagle Breeds Night Dragon
The investigation began with a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service application.
Chinese state media warned citizens in June 2026 about fraudulent apps disguised as official government services, including an APK delivered through attacker-controlled infrastructure.
Researchers linked the app to Flying Eagle after identifying similarities in its file structure, packed resources, asset layout, and four-DEX architecture.
![Hunt.io IP intelligence pivot data for 207.56.30[.]194 (Source: hunt.io)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKANJML_rgbug6MXDoLQ4NbkaFAFh7jN46tQGErllaVDMVjr72eewCwr0ULhmCZeam79BRwKqYKQzhem5qFAAIng-zG403P0LbScsGonXUstcQcIbK5rivjma58t_nTUfaKyx5eA2VfrvLVhr8dQReIw3G3KfaVwYK5WXMvmTLJ64-k4tixVQjSBfGU93f/s1999/Flying+Eagle+Android+RAT+Leaked+Source+Code,+170+Active+Servers,+and+a+New+Platform+Called+Night+Dragon+-+figure+1.webp)
The malicious application was hosted through 110gongan[.]com, a domain using “GongAn,” a Chinese term commonly associated with public security authorities.
Flying Eagle combines an APK builder with a command-and-control (C2) panel. Operators can customize lures, application names, icons, and callback infrastructure before generating signed Android apps.
The builder includes templates impersonating financial services, social platforms, adult streaming services, and public-welfare projects.
The builder also changes package names and class names for each generated APK, making static detection more difficult. It encrypts C2 callback URLs and adds several megabytes of structured, Base64-encoded JSON data to APK assets.
This padding is designed to resemble legitimate SDK cache data rather than random high-entropy content that may attract antivirus scrutiny.
Infrastructure hunting found a recurring AdminPro panel title, a /login?redirect=list/basic-list route, HTTPS redirects, and a distinctive default TLS certificate.

These fingerprints identified 158 Flying Eagle-related servers over 30 days. A separate certificate search located 12 more unique hosts, resulting in 170 observed servers.
Most infrastructure was hosted in Hong Kong, particularly on Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc.
Smaller clusters appeared in the United States, mainland China, Finland, Malaysia, Canada, and Japan. Flying Eagle’s source code was reportedly stolen in early 2026 alongside access to nearly 200 customer databases.
The leak fractured the platform’s criminal ecosystem, allowing multiple actors to distribute patched versions while claiming to remove backdoors, repair connectivity problems, and improve device-control features, hunt.io said.
Two Telegram channels became central to the activity: Yx科技 (Yx Technology) and SQLRCE0. Yx Technology distributed a 388 MB Docker-based Flying Eagle archive called 中国龙.zip in April 2026.
The package included nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default TLS certificate.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.