← Back to Feed

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

July 30, 2026 · Dark Reading · Severity: HIGH

Flying Eagle is an emerging premium Malware-as-a-Service Android RAT that has quickly attracted multiple cybercriminal threat groups. It specializes in building sophisticated information stealers designed specifically to drain victims' bank accounts by intercepting SMS-based two-factor authentication codes, capturing banking credentials, and abusing Android accessibility services. The fact that multiple groups are already operationalizing this RAT indicates a well-polished affiliate ecosystem with strong support infrastructure, lowering the barrier to entry for financially motivated attackers who lack deep technical skills but want to target mobile banking users at scale.

Key Takeaways

  • Flying Eagle is a premium MaaS Android RAT with a mature affiliate program attracting multiple threat groups simultaneously.
  • It targets mobile banking by intercepting SMS 2FA codes and abusing Android accessibility services to steal credentials in real time.
  • The MaaS model means even low-sophistication actors can launch credential-harvesting campaigns against banking customers.
☕ Buy a Coffee