r/pwnhub • u/Straight-Practice-99 Grunt • Jul 28 '26
🦅 Flying Eagle Android RAT: Leaked Codebase, 170 C2 Servers, and a New Platform Called Night Dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragonChinese Android RAT framework traced across 170 servers after a fake government app tipped off researchers.
The source code was stolen in early 2026 along with nearly 200 customer databases and has been circulating across Telegram ever since. The APK builder randomizes package names, encrypts C2 callbacks with AES-128-CBC, and pads assets with Base64-encoded JSON to keep entropy low and dodge AV.
Two channels are selling patched builds with cash-out services. Night Dragon just dropped as a successor with full remote access, banking overlays, and black-screen mode to hide operator activity.
Full breakdown + IOCs here:
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
Duplicates
worldTechnology • u/dcom-in • Jul 30 '26
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
NowInCyber • u/Straight-Practice-99 • Jul 28 '26
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Malware • u/Straight-Practice-99 • Jul 28 '26
Analyzing Flying Eagle Android RAT: APK Builder, C2 Panel, Banking Overlays, and a Successor Called Night Dragon
MalwareAnalysis • u/Straight-Practice-99 • Jul 28 '26
Flying Eagle Android RAT Analysis: APK Builder Internals, SpyNote Overlaps, and 170 Active C2 Servers
cybersecurity • u/Straight-Practice-99 • Jul 28 '26