← Back to Feed
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
July 29, 2026 · The Hacker News · Severity: MEDIUM
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Researchers traced matching control panels and certificates to 170 internet servers, linking the framework to a fake Chinese Public Security service app that targets Android users with capabilities including payment-password capture, keylogging, screen recording, and camera access.
Key Takeaways
- Flying Eagle RAT source code is being actively shared through criminal Telegram channels
- Researchers found matching control panels and certificates on 170 internet servers globally
- The malware disguises itself as a fake Chinese Public Security service application targeting Android users