RESEARCHERS have uncovered a vast cybercrime ecosystem linked to a fake Chinese police app, using the Flying Eagle Android RAT framework. The investigation revealed 170 active servers and two Telegram channels distributing modified versions of the malware. The Flying Eagle toolkit allows criminal actors to create malicious applications that can conduct phishing attacks and remote device management. It was noted that the source code had been leaked, enabling widespread distribution for both paid and free versions.
A new successor, Night Dragon, is in development, enhancing capabilities for credential capture and disguising operator activities. The findings indicate a competitive market for these RAT tools in the Chinese cybercrime landscape.