
RESEARCHERS have uncovered a large‑scale cybercrime operation that hides behind a fake Chinese police application, according to a report published by the Hunt.io threat research team they detail. The campaign relies on the Flying Eagle Android RAT framework, which has been used to spin off more than 170 active command‑and‑control servers and is promoted through two dedicated Telegram channels. Victims are lured into installing the bogus app, which then grants attackers full remote control of the device.
The Flying Eagle kit supplies criminals with a ready‑made toolkit for creating malicious Android programmes that can conduct phishing, harvest credentials and execute remote commands. Because the source code was leaked, both free and paid versions of the builder circulate underground, lowering the barrier for entry. A follow‑on project named Night Dragon is already under development, promising enhanced data‑exfiltration techniques and better camouflage for operator traffic.
The builder includes Docker files for easy deployment, a graphical interface that requires little technical skill, and a library of phishing templates that mimic legitimate banking and government portals. Built‑in mechanisms help the malware evade common mobile antivirus scanners, while Night Dragon adds modules for keystroke logging, screen capture and covert communication over encrypted channels. These features have contributed to a surge in mobile‑banking fraud observed across several Asian markets.
Although the operation primarily targets Chinese‑speaking users, the infrastructure has been spotted in logs from Europe and Southeast Asia, indicating a transnational distribution model. The Telegram channels act as storefronts where actors advertise updates, share custom builds and offer technical support, mirroring the service‑oriented approach seen in many malware‑as‑a‑scheme offerings. Law‑enforcement agencies have noted the difficulty of shutting down such dispersed networks, especially when the underlying code is openly shared.
Defenders should treat any unofficial police or government application with suspicion, verifying the publisher’s signature and only downloading apps from official stores. Network telemetry should be filtered to block connections to the IP ranges and domains associated with the 170 servers listed in the Hunt.io analysis. Mobile threat defence solutions ought to be updated with signatures for the Flying Eagle and Night Dragon families, and user awareness programmes need to highlight the risks of sideloading APKs from unknown sources as highlighted in recent reporting.
Security teams are advised to monitor underground forums and the two Telegram channels for new builds or updates to the Flying Eagle framework, as threat actors frequently rotate payloads to evade detection. Indicators of compromise such as specific package names, certificate hashes and C2 domains should be fed into SIEM and endpoint detection platforms to generate alerts. Collaboration with regional CERTs and information‑sharing groups can help track the evolution of Night Dragon and reduce the window between compromise and response per industry analysis.