zimperium.com • 1h
Flying Eagle Android RAT: Large-Scale Mobile Surveillance Campaign
The "Flying Eagle" Android Remote Access Trojan (RAT) has evolved into a commoditized surveillance ecosystem, utilizing a massive infrastructure of over 170 identified command-and-control (C2) servers. The campaign primarily targets Android users in China via social engineering, distributing malicious payloads disguised as legitimate "Public Security service" applications. Technically, the malware facilitates remote command execution, extensive device surveillance, and the interception of sensitive financial data, including payment passwords. The recent leak of the framework's source code on criminal Telegram channels signals a transition from targeted operations to broad, large-scale availability for diverse threat actors.