Flying Eagle: The Android RAT Impersonating a Chinese Police App, Now Out of Control After Source Code Leak
The Flying Eagle Android RAT creates variants like Night Dragon after a source code leak. It steals credentials and hijacks devices via fake police apps.
Illustrative image generated with AI
An Android application masquerading as a provincial Chinese Public Security service has exposed the malicious framework Flying Eagle (飞鹰). The fake app caught researchers’ attention, and as early as June 2026, Chinese state media had already issued a warning to citizens. The investigation quickly led to a full criminal ecosystem built around a complete Remote Access Trojan (RAT) with capabilities ranging from credential theft to total device takeover.
Leaked Source Code Multiplies Variants
In early 2026, Flying Eagle’s source code hit the web. From that moment on, the toolkit ceased to be a closed commercial product and turned into a project accessible to anyone. Variants produced by the original builder began circulating through two Telegram channels: SQLRCE0 and Yx科技. Researchers identified 170 active servers by fingerprinting control panels and TLS certificates; another 12 servers exposed the default certificate of the Docker version of the malware, a sign of now-automated distribution.
The SQLRCE0 channel distributed fixes to the leaked code and on June 23, 2026, announced the successor Night Dragon (夜龙), which reached version 2 on July 12. The barrier to entry dropped even further when, in April, a working Docker container was released for free. Those who wanted a “fixed” version could purchase it for 2000 USDT.
What Flying Eagle Does (and How It Hides)
The integrated builder generates malicious APKs with randomized class names, AES‑128‑CBC obfuscation of command-and-control URLs, and fake JSON padding to evade antivirus checks. Among the features found:
- Keylogging and screenshot capture
- Real-time audio and video recording
- Access to SMS, image gallery, and file system
- Phishing overlays designed for banking and crypto apps
The overlays target WeChat, Alipay, ICBC, Agricultural Bank, Construction Bank, and wallets like TokenPocket and imToken. The goal is to capture credentials directly from the user interface, without the victim noticing the overlay.
All Docker and Windows XAMPP variants share a revealing typo: the internal key “SECRIT_KEY” (instead of “SECRET_KEY”). This detail made tracking the servers easier.
Night Dragon: The Heir with Black Screen and One‑Click Capture
Night Dragon adds a black screen mode that simulates a fake system update, hides the app icon, and introduces overlays for credential theft with a single touch. A Night Dragon control panel observed on July 31, 2026, showed 46 devices, at least 29 of them connected, all located in China. Development is active, and the SQLRCE0 channel keeps publishing updates, making this RAT even harder for victims to detect.
Crime Infrastructure and Centralized Cash‑Out
Beyond malware distribution, the Flying Eagle ecosystem offers a monetization service. The Yx科技 channel operates as operational support and handles the cash-out of Alipay and WeChat accounts drained from victims, with commissions ranging from 20% to 50%. Phishing campaigns target Chinese users through lures impersonating public security apps, adult streaming, TikTok, financial platforms, and welfare projects. The draining of digital wallets and bank accounts happens directly from compromised devices.
What Defenders and Users Can Do
The modular nature and open code make it difficult to stop the phenomenon, but some countermeasures are already known:
- Block indicators of compromise: panels with the title “AdminPro”, HTTP 302 redirects, anomalous
Strict-Transport-Securityheaders, and the default TLS certificate of the Docker distribution. - Disable installation from unknown sources on Android devices and download apps exclusively from official stores.
- Monitor traffic to domains and IPs that expose the string “SECRIT_KEY” and the fingerprints of Flying Eagle/Night Dragon panels.
- Raise user awareness about fake government apps, in line with the alerts already issued by Chinese authorities in June 2026.
The combination of source code leak, accessible builder, and turnkey cash‑out services has turned Flying Eagle into a widespread and persistent threat, with a successor already operational that promises to complicate the landscape further.
Sources
This article is an original reworking based on the sources below.




