Researchers have uncovered a large-scale operation of the Android Remote Access Trojan (RAT) known as Flying Eagle, linked to the leaked malware framework Flying Eagle. The platform was identified across 170 servers after investigators traced a fake Chinese Public Security Bureau application back to shared infrastructure, TLS certificates, panel fingerprints, and Telegram-based malware distribution. The activity appears financially motivated, primarily targeting Chinese Android users with fraudulent government-service, financial, adult-content, and social-media lures.

A newer Android RAT platform named Night Dragon is being promoted by an actor using the SQLRCE0 Telegram account, potentially indicating a next stage in this malware ecosystem.

This warning was issued by Chinese state media in June 2026, advising citizens to avoid fraudulent apps disguised as official government services and delivered through attacker-controlled infrastructure. The leak disrupted the platform’s criminal ecosystem, enabling multiple actors to distribute patched versions while falsely claiming to remove backdoors, repair connectivity issues, and enhance device-control features, hunt.io stated. In April 2026, this channel hosted the distribution of an extensive Docker-based Flying Eagle archive named "中国龙.zip."

The package included nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default TLS certificate. Utilizing ANY.RUN could help detect and mitigate blind spots in security operations to prevent threats from escalating and minimize response costs and business disruptions.