Night Dragon, also known as 夜龙, is an Android remote-control malware platform assessed to be a successor to the Flying Eagle criminal ecosystem. It emerged in June 2026 and appears to be a separate build rather than a simple rebrand of Flying Eagle. The malware is associated with financially motivated operators targeting Chinese users, particularly through lures themed around government services, banking, payment platforms, and cryptocurrency wallets.
Night Dragon provides remote access and device-management capabilities through a management panel that exposes live screen viewing, access to text messages, photos, audio recording, camera capture, file management, and related post-compromise control functions. Reported theft functionality includes password-capture and phishing overlays aimed at banking and payment applications as well as cryptocurrency wallet apps. Its operator-facing feature set also includes stealth mechanisms such as automatic hiding of the application icon after installation and a fake system-update or black-screen display intended to conceal attacker activity while the device remains under control.
Observed reporting links Night Dragon to the Telegram actor SQLRCE0, which introduced the platform on June 23, 2026, while version 2 was already under development by mid-July 2026. The broader ecosystem around Night Dragon overlaps with actors previously involved in distributing modified Flying Eagle builds and monetizing stolen access. Available evidence indicates Night Dragon is used for credential theft, phishing-assisted fraud, and broader remote surveillance and control of infected Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers linked the Flying Eagle Android RAT to fake police apps... The APK generation module accepts user-defined lured text, application names, icons, and C2 callback addresses, then builds a signed APK using one of two base templates.
The project was described as supporting password capture for banking and payment apps... It could also push phishing overlays for payment services, banks, and cryptocurrency wallets.
The original class identifiers reflect the malware's core capabilities: ... LiveKeysStrok - keylogging
The project was described as supporting password capture for banking and payment apps... It could also push phishing overlays for payment services, banks, and cryptocurrency wallets.
The original class identifiers reflect the malware's core capabilities: ... LiveKeysStrok - keylogging
A phishing overlay system allows operators to deploy credential capture prompts for specific applications, with single-click shortcuts for Alipay, WeChat, and major Chinese banks... in addition to cryptocurrency wallets TokenPocket and imToken.
Once installed, Flying Eagle can abuse Android Accessibility Services, capture screens, log keystrokes, access the camera, and display fake login pages over legitimate apps.
Flying Eagle is not just a malicious app. It is a complete framework that allows an operator to build customized Android packages and manage compromised devices from a web panel.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely successor platform to Flying Eagle, introduced in June 2026 and already evolving with a version 2 under development.
An independently developed successor platform to Flying Eagle for Android device compromise. It includes black-screen mode with a fake system update, automatic icon hiding after installation, phishing overlays for Alipay, WeChat, major Chinese banks, and cryptocurrency wallets, plus full remote access to infected devices.
A newer Android remote-control kit related to the same criminal ecosystem, capable of password capture for banking and payment apps, hiding its icon after installation, showing a fake system-update screen, and providing access to live screens, messages, photos, audio, cameras, files, and phishing overlays for banks, payment services, and cryptocurrency wallets.
A newer Android remote-control kit supporting password capture for banking and payment apps, icon hiding after installation, a fake system-update screen, live device access, and phishing overlays targeting payment services, banks, and cryptocurrency wallets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.