Flying Eagle is an Android remote access trojan framework used in a financially motivated criminal ecosystem primarily targeting users in China. It has been distributed through fake Android applications impersonating public-security and other trusted services, and operators can use its builder to generate customized signed APKs with chosen app names, icons, lure text, and command-and-control settings. Observed lures have imitated government-service, financial, adult-content, and social-media applications.
The malware provides full device-management capabilities through a web-based operator panel and supports extensive surveillance and theft functions on compromised Android devices. Documented capabilities include phishing overlays for banking, payment, adult-content, and government-service applications; capture of payment credentials; keylogging; screen recording or capture; camera access; and remote command execution. Generated samples have also been observed abusing Android Accessibility Services to gain elevated control and facilitate malicious actions. The builder incorporates obfuscation and defense-evasion features, including randomized package and class names, encrypted embedded callback information, and padding intended to reduce antivirus detection.
Flying Eagle’s source code was reportedly stolen and leaked in early 2026 together with customer data, after which modified variants were circulated by multiple criminal actors through Telegram channels. Investigations linked the framework to a large server footprint, with at least 170 internet-exposed systems associated through panel fingerprints, certificates, and shared deployment characteristics, indicating a broad and resilient operator ecosystem rather than a single isolated campaign. The activity has been associated with fraud enablement and cash-out support, underscoring Flying Eagle’s role as a mature Android malware platform supporting credential theft and broader post-compromise control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
To evade antivirus detection, the builder pads APKs with fake JSON configuration data and encrypts C2 callback URLs using AES-128-CBC with hardcoded cryptographic parameters. At build time all of those get replaced with randomized 8-to-14 character strings, so static analysis hits a wall immediately.
This kit enables attackers to capture payment passwords and keystrokes... | This kit enables attackers to ... deploy phishing prompts for financial, adult-content, and government applications.
The original class names in the source code tell you exactly what the tool does: RecordPayPassword, LiveKeysStrok, ScreenCaps, Webjector, CameraCap.
The malware is designed to give attackers extensive control over compromised devices, enabling surveillance, data theft, and remote command execution.
This kit enables attackers to capture payment passwords and keystrokes... | This kit enables attackers to ... deploy phishing prompts for financial, adult-content, and government applications.
The original class names in the source code tell you exactly what the tool does: RecordPayPassword, LiveKeysStrok, ScreenCaps, Webjector, CameraCap.
A recent investigation uncovered infrastructure supporting the Flying Eagle Android remote access trojan, identifying more than 170 command-and-control servers linked to the campaign.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan designed to give attackers extensive control over compromised devices, enabling surveillance, data theft, and remote command execution.
Android malware that uses fake government-themed apps as an infection vector and includes APK generation, full-featured command-and-control device management, and phishing overlays for credential theft against banking, adult, and government apps.
A leaked Android remote access trojan framework that combines APK generation with full-featured C2 device management. It supports phishing overlays for financial, adult, and government service apps, and provides capabilities such as credential theft, screen capture, camera access, and remote device control.
Android remote access trojan framework distributed via a fake Public Security service app. It can capture payment passwords and keystrokes, record screens, access cameras, and display phishing prompts targeting financial, adult-content, and government applications. It also uses Android accessibility services for privilege escalation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.