The record
Written from the 1 report below. Nothing here is unsourced.
- Source code for Flying Eagle, an Android remote access trojan framework, is being shared through criminal Telegram channels, and researchers have linked it to a fake Chinese public security app that can steal payment data and control devices.
- Hunt.io and researcher NetAskari identified 170 servers with matching infrastructure fingerprints, though this count does not equal confirmed victims or control servers.
- The kit lets criminals easily build signed malicious apps with features like keystroke capture, screen recording, and camera access.
- Chinese authorities have warned users to delete the fraudulent app, scan devices, and change passwords if affected.
What to watch next
- Further spread of Flying Eagle variants through Telegram channels SQLRCE0 and Yx Technology
- Development and distribution of the related Night Dragon Android kit, which had a second version in development as of July 12
- Verification of the unconfirmed claim that 189 Flying Eagle servers were compromised and their databases exfiltrated
Coverage1
1 report
English national1
All filed from India
Named China · Android · Public Security service application · China's National Cybersecurity Notification Center · Chinese authorities · Flying Eagle · Hunt.io · McAfee · NetAskari · Night Dragon · SpyNote · SQLRCE0 · Telegram
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
