Close Menu
NCIJ Network NCIJ Network
    What's Hot

    xAI’s last-minute scramble to stop Minnesota’s anti-nudification law

    July 30, 2026

    Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms

    July 30, 2026

    “There’s no free money forever”: Twenty One Capital’s new CEO warns the Bitcoin treasury playbook is dying

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • xAI’s last-minute scramble to stop Minnesota’s anti-nudification law
    • Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms
    • “There’s no free money forever”: Twenty One Capital’s new CEO warns the Bitcoin treasury playbook is dying
    • Daily multivitamin may help older adults stay independent
    • Northern Virginia’s House members take Big Tech cash while residents push back on data centers • OpenSecrets
    • U.S.-Saudi Strikes on Iraqi Militias Add New Front to Iran War
    • India’s CJP protests: Why tech alone won’t stop exam paper leaks
    • The first election of the Andy Burnham era is already here – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ‘Flying Eagle’ Full-Service Mobile RAT Builder Wings Across China

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 30, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Chinese cybercriminals have been using full-service mobile malware frameworks to steal money from popular finance apps.

    On June 18, China’s National Cybersecurity Reporting Center issued a warning on WeChat to the general public. Cybercriminals were masquerading as provincial public security services, spreading a fake app that promised citizens “one-stop handling” of public safety issues online. Anyone who downloaded the app unwittingly infected their mobile device with information-stealing malware. The warning also listed two IP addresses associated with the campaign.

    Those IP addresses led the independent researcher NetAskari, and hunt.io, down a rabbit hole. At the end of it was a substantial cybercriminal ecosystem built around a sophisticated, all-in-one malware-as-a-service (MaaS) builder called “Flying Eagle.”

    White Glove MaaS With Flying Eagle Cybercrime Kit

    Flying Eagle supplies all the infrastructure and features any ordinary hacker would need to build their own easy mobile malware campaign. Nowhere is this point more obvious than in how it’s distributed. Instead of files on some server somewhere, Flying Eagle is packaged as a complete Docker deployment. Every user gets their own goodie bag with a Web server, a WebSocket server, PHP, and MySQL.

    Related:Weak Security Continues to Fuel Russian Cyberattacks

    “Docker as a concept invites itself to cybercriminals as much as normal software developers,” NetAskari tells Dark Reading. “Especially if you are in the business of deploying fast, lowering the bar for entry, etc., Docker makes a lot of sense. It keeps things clean, you can deploy it at almost any remote server with little investment in time or adoption.”

    Besides the necessary Docker components, users get Android Package Kit (APK) and software development kit (SDK) build tools. It includes Java 11, and a default Transport Layer Security (TLS) certificate. And it offers a variety of phishing templates, including those that mimic TikTok, popular adult services and financial apps, and public welfare projects.

    NetAskari marvels at the flexibility and ease of use of modern MaaS offerings. “What I found quite fascinating is how comfortable and modular those kits are by now. Graphical user interfaces (GUIs), clear structures and workflows, templates, ready-to-deploy frameworks. It doesn’t really require a lot of skill anymore to set up modest systems to launch, breach, and extract data from average hardened devices. This is clearly tailored more toward ordinary criminals than sophisticated hackers,” he says.

    MaaS In-Depth: A Look at Flying Eagle’s Talons

    When the researchers stood up a test instance of Flying Eagle, they found that within the APK builder, the developers included a variety of features for helping users evade static detection out of the box. For example, it conceals names of classes in its code that might tip off antivirus (AV) engines, and it ensures that each new sample of Flying Eagle malware is unique by replacing its hardcoded package name with a randomly generated but seemingly legitimate name such as “com.cloud.manager.core.”

    Related:China’s Webworm Uses Discord, Microsoft Graphs to Hack EU Governments

    “The evasion work on the APK builder is what I keep coming back to,” says hunt.io head of research Esteban Borges. “To pad out its samples it avoids random bytes, which can trip antivirus heuristics, and instead injects a few megabytes of Base64 JSON dressed up as SDK config caches. That keeps entropy low and looks like ordinary app data, and the developer even left a comment saying that was the point.”

    Flying Eagle samples can steal a wide variety of data off mobile devices, including payment credentials and screengrabs. They support keylogging and camera access. They can abuse accessibility services to escalate privileges, and inject overlays into government, pornographic, and financial services apps.

    The Chinese Cybercriminal Underground & Night Dragon

    Originally, Flying Eagle was shared within closed circles. It only leaked into the wider Chinese cybercriminal ecosystem earlier this year. Shortly thereafter a Telegram channel was created to leverage the situation, called “SQLRCE0,” which helped spread the tool, offer technical support to users, and market a “repaired” version of the original for $2,000 in Tether cryptocurrency. A couple of months later, a second major Telegram channel was formed to do some version of the same thing.

    Related:Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

    In the spring, when the Chinese government spread its warning about Flying Eagle-generated fake apps, SQLRCE0 was ready with a response. Five days after the notice went out, it released a new Android remote control kit called “Night Dragon.”

    To date, Night Dragon is nowhere near as popular as Flying Eagle. The researchers could only find a couple of active servers running it, compared to its predecessor’s hundreds. Yet it might be the more advanced of the two. It can capture live views of victims’ screens, their microphones’ audio, and their cameras. It can access SMS messages, photo galleries, and other files. It injects overlays into popular Chinese finance apps like AliPay and WeChat, cryptocurrency wallet platforms, and major state-owned banks’ apps, including the Agricultural Bank of China, China Construction Bank, and the Industrial and Commercial Bank of China (ICBC). To keep all this mischief a secret, Night Dragon hides its own app icon, and lets attackers force display an artificial black update screen to victims while they’re performing hands-on activity.

    “China is the country of ‘big numbers’ that also applies to cyber criminals. The cybercrime environment is probably the most diverse in the world,” NetAskari says. “Despite being the world’s biggest surveillance state, China still struggles to eradicate it. But they are making progress.”

    Builder China Eagle Flying FullService mobile RAT Wings
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms

    SE Asian Cybercriminal Syndicates Become a Global Power

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    Cisco warns of FMC static credential flaw exploited in zero-day attacks

    Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    xAI’s last-minute scramble to stop Minnesota’s anti-nudification law

    July 30, 2026

    Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms

    July 30, 2026

    “There’s no free money forever”: Twenty One Capital’s new CEO warns the Bitcoin treasury playbook is dying

    July 30, 2026

    Daily multivitamin may help older adults stay independent

    July 30, 2026
    Latest Posts

    Who’s in Andy Burnham’s new Labour cabinet?

    July 22, 2026

    Streeting apologises after early prisoner release comments heard on mic

    July 22, 2026

    Mehr Risikokapital, mehr Rüstung – Reiches Start-up-Plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    xAI’s last-minute scramble to stop Minnesota’s anti-nudification law

    July 30, 2026

    Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms

    July 30, 2026

    “There’s no free money forever”: Twenty One Capital’s new CEO warns the Bitcoin treasury playbook is dying

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.