Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

    Date: 07/31/2026

    Severity: High

    Summary

    A fake Public Security Bureau app distributed through attacker-controlled domains served as the primary infection vector for Flying Eagle malware. Chinese state media issued a warning in June 2026 about fraudulent apps masquerading as official government services. Flying Eagle provides both APK generation and full-featured C2 device management, along with phishing overlays targeting banking, adult, and government apps. Its source code was leaked in early 2026 alongside nearly 200 customer databases, leading to the emergence of multiple modified variants. Telegram channels such as SQLRCE0 and Yx科技 are distributing patched versions of the malware and offering operational support and cash-out services. Researchers also identified a likely successor platform, Night Dragon (夜龙), introduced in June 2026, with version 2 already under development.

    Indicators of Compromise (IOC) List

    Domains/URLs

    110gongan.com

    fusu.us.ci

    ls.j2x8a.top

    alcs.xyttkx.cc

    txl.xyttkx.cc

    h5.xyttkx.cc

    s.orove.cn

    IP Address 

    207.56.30.188

    207.56.30.194

    108.187.7.66

    108.187.7.71

    77.105.161.235

    154.44.25.12

    85.137.253.48

    Hash  

    c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd

    0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f

    4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164

    5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b

    b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3

    d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e

    1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a

    773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df

    82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7

    7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af

    Filenames 

    Eaod85401.php

    Eaod29251.php

    EaodWorker.exe

    ApkBuilder.php

    中国龙.zip

    飞鹰控打包.zip

    Telegram Channel 

    @SQLRCE0

    Yx科技 (Yx Technology)

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "ls.j2x8a.top" or url like "ls.j2x8a.top" or siteurl like "ls.j2x8a.top" or domainname like "110gongan.com" or url like "110gongan.com" or siteurl like "110gongan.com" or domainname like "h5.xyttkx.cc" or url like "h5.xyttkx.cc" or siteurl like "h5.xyttkx.cc" or domainname like "alcs.xyttkx.cc" or url like "alcs.xyttkx.cc" or siteurl like "alcs.xyttkx.cc" or domainname like "fusu.us.ci" or url like "fusu.us.ci" or siteurl like "fusu.us.ci" or domainname like "txl.xyttkx.cc" or url like "txl.xyttkx.cc" or siteurl like "txl.xyttkx.cc" or domainname like "s.orove.cn" or url like "s.orove.cn" or siteurl like "s.orove.cn"

    Detection Query 2 :

    dstipaddress IN ("77.105.161.235","108.187.7.66","154.44.25.12","108.187.7.71","85.137.253.48","207.56.30.194","207.56.30.188") or srcipaddress IN ("77.105.161.235","108.187.7.66","154.44.25.12","108.187.7.71","85.137.253.48","207.56.30.194","207.56.30.188")

    Detection Query 3 :

    sha256hash IN ("773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df","4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164","b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3","d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e","c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd","0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f","5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b","1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a","82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7","7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and objectname IN ("Eaod85401.php","Eaod29251.php","EaodWorker.exe","ApkBuilder.php","中国龙.zip","飞鹰控打包.zip")

    Detection Query 5 :

    technologygroup = "EDR" and objectname IN ("Eaod85401.php","Eaod29251.php","EaodWorker.exe","ApkBuilder.php","中国龙.zip","飞鹰控打包.zip")

    Reference:    

    https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon                            


    Tags

    MalwareThreat ActorAndroid MalwareRATChinaFake WebsiteGovernment Services and FacilitiesPhishingFinancial ServicesTelegram

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags