Flying Eagle Tech is the developer identity associated with Flying Eagle (飞鹰), an Android remote access trojan framework used in a Chinese-language cybercrime ecosystem. The framework functions as both a malware builder and an operator management platform, allowing users to generate signed malicious Android applications with customized lure text, branding, icons, and command-and-control settings, then manage infected devices through a centralized panel. Following a source-code theft in early 2026, Flying Eagle evolved from a controlled commercial malware offering into a more broadly distributed criminal toolkit, with modified variants circulated through Telegram channels and used by multiple actors. Flying Eagle has been used in fraudulent Android applications impersonating police and public-service apps as well as financial, adult-content, social-media, and public-welfare themes. Its capabilities include phishing overlays for credential capture, device management, screen capture, camera access, and anti-analysis or defense-evasion measures such as randomized class names and APK padding intended to reduce antivirus detection. Operational infrastructure associated with the ecosystem has included large numbers of active servers and both Docker- and Windows-based deployments. Telegram-based operators and resellers tied to the ecosystem have advertised operational support, cash-out services, and instructions for draining mobile payment accounts, indicating a financially motivated criminal operation. A successor platform called Night Dragon (夜龙) emerged in 2026 as a separate build associated with the same broader ecosystem. Night Dragon added features such as black-screen fake update mode, icon hiding, and credential-theft overlays targeting Chinese banking, payment, and cryptocurrency wallet applications. Known associated names within this ecosystem include Flying Eagle, 飞鹰, Night Dragon, and 夜龙.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.