Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform.
The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers found a misspelled environment variable, SECRIT_KEY, in the source archive and used it to locate an open directory. The directory exposed a Windows XAMPP deployment of the same Flying Eagle codebase.
Hunt.io and NetAskari investigated the leaked Flying Eagle Android RAT framework and expanded from the initial IPs using Let's Encrypt certificate-subject pivots and an AdminPro panel fingerprint. They identified 170 active servers, many hosted by Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc.
A June 2026 Chinese state media notice identified two IP addresses tied to the Flying Eagle Android RAT. Hunt.io and NetAskari later used those IPs as the starting point for broader infrastructure analysis.
Hunt.io reported that Flying Eagle source code was stolen in early 2026 along with nearly 200 customer databases. The reference says Telegram channels including SQLRCE0 and Yx Technology then distributed patched builds and operator support, helping broaden use of the malware framework.
The investigation identified and documented a successor platform called Night Dragon. The report said the newer platform targets Chinese users.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
zimperium.com
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcereddit.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.