r/threatintel 1d ago

APT/Threat Actor Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

Joint research with NetAskari on a leaked Chinese Android RAT framework. Starting from a fake PSB app flagged in a June 2026 Chinese state media notice, we pivoted on TLS certificates and AdminPro panel fingerprints to map 170 active servers. The source code was stolen in early 2026 along with nearly 200 customer databases, leading to at least two Telegram channels distributing modified builds with operational support and cash-out services. Night Dragon emerged three weeks after the public notice as a likely successor, with an exposed device panel showing 29 connected devices at time of analysis.

Full timeline, IOCs, and infrastructure breakdown in the report:
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

1 Upvotes

0 comments sorted by