yx科技 is a Chinese-language criminal support and sales channel associated with the Flying Eagle Android malware ecosystem. It operated around the leaked Flying Eagle, or 飞鹰, Android RAT framework and served as an operational enablement node for fraud and account-draining activity rather than as a purely technical malware-development brand. The channel advertised and supported monetization of compromised accounts, including step-by-step guidance for draining Alipay and WeChat accounts, referred to victims as “fish,” and offered cash-out services for a percentage of stolen funds. Within the broader Flying Eagle ecosystem, yx科技 was linked to distribution and operational support for modified versions of the leaked malware codebase. Flying Eagle enabled operators to generate signed malicious Android applications, manage infected devices through a command-and-control panel, and deploy phishing overlays against financial and government-service applications. Activity associated with this ecosystem indicates capabilities aligned with initial access through trojanized Android apps, credential theft via overlays, post-compromise monetization, and exfiltration of victim data needed to facilitate fraud. The actor’s observed behavior is consistent with financially motivated mobile cybercrime targeting Chinese users of major payment platforms. High-confidence reporting supports its role in fraud operations and cash-out enablement within the Flying Eagle criminal ecosystem, but does not firmly establish yx科技 as the primary developer of the malware family itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.