Source code for a sophisticated Android remote access trojan known as Flying Eagle is now circulating on criminal Telegram channels, raising the likelihood of wider abuse by threat actors. Researchers from Hunt.io, working with independent researcher NetAskari, have tied the framework to matching control panels and digital certificates found across 170 internet-facing servers, according to a report from The Hacker News on July 29.

The malware has been distributed through a counterfeit Android application impersonating "公安一网通办," a legitimate Chinese public security one-stop online service. Once installed, the trojan grants operators extensive remote control over infected devices. The kit supports payment-password interception, positioning it as a direct tool for financial fraud rather than simple data collection.

Security investigators mapped the infrastructure by correlating unique control-panel signatures and certificate details associated with the Flying Eagle framework. The scale of the discovered server footprint—170 hosts—indicates an already mature operation capable of supporting large numbers of victims. With the full source code now freely available in underground communities, the barrier to entry for less-skilled criminals has dropped sharply. Observers expect a rise in customized variants that retain the core payment-interception features while altering indicators to evade detection.

The campaign's social-engineering approach relies on the high trust Chinese users place in official government service apps. By cloning the branding and interface of a recognized public-security platform, operators increase the chance that targets will grant the malicious app the permissions it needs, including accessibility services that enable keystroke logging and overlay attacks on banking and payment interfaces.

For the broader mobile-security community, the incident underscores several persistent challenges. First, the rapid weaponization of leaked malware source code continues to shorten the time between initial discovery and mass exploitation. Second, Android's permission model, while improved in recent releases, still allows trojans that successfully socially engineer users to achieve deep device control. Third, financially motivated groups are refining their tooling specifically around mobile payment ecosystems prevalent in Asia.

Defenders monitoring Chinese-language threat activity should prioritize detection of the known Flying Eagle control-panel fingerprints and associated certificates. Application-vetting processes for enterprise mobile device management solutions may also benefit from updated signatures that flag apps requesting unusual combinations of accessibility, SMS, and overlay permissions under government-service branding.

While the current campaign focuses on users inside China, the public release of the source code means adapted versions could appear in other markets that rely heavily on mobile payments. Organizations supporting cross-border workforces or operating Android fleets in the region have a clear incentive to review their mobile threat-defense posture and user-awareness materials around sideloaded or look-alike government apps.

The Flying Eagle case illustrates how quickly a capable RAT framework can scale once its internals become public. Continued tracking of the 170-server cluster and any newly emerging variants will be essential for containing the next wave of attacks built on this leaked codebase.


名為 Flying Eagle 的複雜 Android 遠端存取木馬源碼,現時正於犯罪 Telegram 頻道流通,增加了被威脅行為者更廣泛濫用的可能性。根據 The Hacker News 於 7 月 29 日的報導,Hunt.io 的研究人員與獨立研究員 NetAskari 合作,已將該框架與橫跨 170 台面向互聯網伺服器上發現的匹配控制面板及數碼憑證聯繫起來。

該惡意軟件透過一款假冒「公安一網通辦」的 Android 應用程式進行分發,該應用程式模仿了一個合法的中國公安一站式網上服務。一旦安裝,木馬便賦予操作者對受感染裝置廣泛的遠端控制權。該工具包支持攔截支付密碼功能,使其直接成為金融詐騙的工具,而非僅僅用於簡單的數據收集。

安全調查人員透過關聯與 Flying Eagle 框架相關的獨特控制面板特徵及憑證細節,繪製出其基礎設施圖。所發現的伺服器規模——170 台主機——表明這已經是一個成熟的操作體系,能夠支持大量受害者。隨著完整源碼現在在地下社群中自由流通,技術較弱的犯罪分子進入門檻已大幅降低。觀察家預計將會出現更多定制變種,這些變種將保留核心的支付攔截功能,同時修改特徵以規避偵測。

該攻擊活動的社會工程手法,依賴中國用戶對官方政府服務應用程式的高度信任。透過複製一個知名的公安平台品牌和界面,操作者增加了目標用戶授予惡意應用程式所需權限的可能性,包括可實現鍵盤記錄以及銀行和支付界面覆蓋攻擊的無障礙服務功能。

對更廣泛的流動裝置安全社群而言,此事件凸顯了幾個持續存在的挑戰。首先,洩漏的惡意軟件源碼被迅速武器化,持續縮短從初步發現到大規模利用的時間。其次,Android 的權限模型雖然在近期版本中有所改進,但仍然允許成功透過社會工程欺騙用戶的木馬實現對裝置的深度控制。第三,以經濟利益為動機的組織,正專門針對亞洲普遍存在的流動支付生態系統來優化其工具。

監控中文威脅活動的防禦者,應優先偵測已知的 Flying Eagle 控制面板指紋及相關憑證。針對企業流動裝置管理解決方案的應用程式審核流程,亦可能受益於更新的特徵庫,用以標記那些在政府服務品牌下,要求不尋常的無障礙服務、短訊及覆蓋權限組合的應用程式。

雖然目前的攻擊活動聚焦於中國境內用戶,但源碼的公開發布意味著,改編版本可能出現在其他高度依賴流動支付的市場。支持跨境工作團隊或在該地區營運 Android 裝置群組的組織,有明確的動機去審視其流動威脅防禦態勢,以及針對側載或偽裝政府應用程式的用戶意識教育材料。

Flying Eagle 案例說明,一旦一個功能強大的 RAT 框架內部結構公開,其擴展速度可以有多快。持續追蹤該 170 台伺服器集群及任何新出現的變種,對於遏制基於此洩漏代碼庫的下一波攻擊至關重要。

新聞來源 / Original News Source