Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Summary

The source code for the Flying Eagle Android remote access trojan (RAT) is being shared on criminal Telegram channels. Security researchers have identified 170 servers hosting its control panels and certificates, and linked the malware to a fake Chinese Public Security service application designed to target Android users.

IFF Assessment

FOE

The circulation of the source code for a sophisticated Android RAT indicates a growing threat and potential for wider exploitation by malicious actors.

Defender Context

The availability of Flying Eagle RAT source code on criminal channels poses a significant risk to Android users, particularly those in China. Defenders should be aware of campaigns leveraging this RAT and monitor for its deployment, especially in targeted regions. This highlights the ongoing threat of easily accessible, sophisticated malware tools in the underground.

Read Full Story →