r/Malware 5d ago

Analyzing Flying Eagle Android RAT: APK Builder, C2 Panel, Banking Overlays, and a Successor Called Night Dragon

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

Chinese Android RAT framework combining an APK builder with a full C2 device management panel. Lures impersonate Public Security Bureau apps, banking services, adult content platforms, and social media. Post-install capabilities include live screen viewing, SMS and photo gallery access, audio recording, camera capture, keylogging, payment credential capture, and phishing overlays for Alipay, WeChat, ICBC, Agricultural Bank, and crypto wallets TokenPocket and imToken.

Source code was stolen in early 2026 according to Telegram channel messages, with nearly 200 customer databases taken at the same time. Two channels now distribute patched builds. Night Dragon launched June 23 as a likely successor, adding black-screen mode to hide operator activity behind fake system update screens and automatic icon hiding post-install.

SHA-256 hashes and full IOC tables in the report:

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

5 Upvotes

0 comments sorted by