Flying Eagle (飞鹰) is an undocumented Android malware builder and device-control framework used in a financially motivated criminal ecosystem. It enables operators to generate customized malicious Android applications and manage infected devices through a web-based command-and-control panel. The framework has been distributed through Telegram channels such as Yx科技 and SQLRCE0, which also circulated modified builds after the source code was reportedly leaked in early 2026 along with customer data. Researchers assessed those distributors were likely not the original developers, but key actors in the downstream criminal ecosystem. Flying Eagle supports end-to-end Android fraud operations. Its builder allows operators to customize lure text, application branding, icons, and callback configuration, while producing obfuscated APKs designed to hinder static detection. Reported capabilities include credential theft, keylogging, screen capture, camera access, accessibility abuse, web injection, phishing overlays, and remote device control. Generated samples have been identified as SpyNote-family Android malware. The framework also incorporates anti-detection measures, including randomized package and class naming and padding intended to reduce antivirus scrutiny. Operational use has centered on social-engineering lures aimed primarily at Chinese users, including fake government-service applications, financial themes, adult-content lures, and social-media themes. Fraud guidance shared by associated Telegram channels included instructions for draining mobile payment accounts and arranging cash-out services, indicating a mature criminal monetization model. Infrastructure linked to Flying Eagle has been concentrated heavily in Hong Kong-hosted environments, with additional infrastructure observed in several other countries. The broader ecosystem around Flying Eagle appears to be evolving. SQLRCE0 later promoted Night Dragon (夜龙), a likely successor Android remote-access platform with similar fraud-oriented capabilities, including password capture, phishing overlays, remote screen viewing, SMS access, audio and camera capture, file management, and icon-hiding features. Overall, Flying Eagle represents a Chinese-language Android cybercrime toolkit and operator ecosystem focused on mobile credential theft, device compromise, and financial fraud against Chinese citizens.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.