Executive Summary
In July 2026, security researchers discovered that the source code for the Flying Eagle Android Remote Access Trojan (RAT) had been leaked and was circulating in criminal Telegram channels. This leak led to the identification of 170 servers hosting control panels and certificates associated with the malware. The Flying Eagle RAT was distributed through a counterfeit '公安一网通办' Public Security service application targeting Android users in China. Once installed, the malware granted attackers extensive control over infected devices, enabling unauthorized access to sensitive information and potential financial theft.
The proliferation of the Flying Eagle RAT underscores a growing trend of sophisticated Android malware campaigns leveraging social engineering tactics and exploiting trust in official-looking applications. This incident highlights the critical need for robust mobile security measures and user education to prevent similar attacks in the future.
Why This Matters Now
The leak and widespread distribution of the Flying Eagle RAT source code have significantly lowered the barrier for cybercriminals to launch sophisticated Android malware attacks. This development poses an immediate threat to mobile device security, emphasizing the urgency for enhanced protective measures and user vigilance.
Attack Path Analysis
The Flying Eagle Android RAT was disseminated through a counterfeit Public Security service application, leading to the initial compromise of Android devices. Upon installation, the malware exploited Android accessibility services to escalate privileges, enabling it to perform actions without user consent. Subsequently, the RAT established command and control channels, allowing remote operation of the infected devices. The malware then exfiltrated sensitive data, including payment information and keystrokes, to attacker-controlled servers. Finally, the attackers utilized the stolen data for financial gain, causing significant impact to the victims.
Kill Chain Progression
Initial Compromise
Description
The Flying Eagle Android RAT was distributed via a counterfeit 'Public Security' service application, leading to the initial compromise of Android devices.
Related CVEs
CVE-2024-43093
CVSS 7.3Incorrect Unicode normalization in ExternalStorageProvider.java allows attackers to bypass file path filters, leading to local privilege escalation.
Affected Products:
Google Android – 12, 12L, 13, 14, 15
Exploit Status:
exploited in the wildCVE-2026-20428
CVSS 6.7Out-of-bounds write in MediaTek display component allows local attackers with System privilege to escalate privileges.
Affected Products:
MediaTek MT6739 – All versions prior to patch
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Obfuscated Files or Information
Capture SMS Messages
Input Capture
Audio Capture
Location Tracking
Access Contact List
Access Call Log
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Flying Eagle Android RAT impersonating Chinese Public Security services creates severe risks for government mobile operations and citizen service delivery platforms.
Banking/Mortgage
RAT's payment-password targeting capabilities pose critical threats to mobile banking security, customer authentication systems, and financial transaction protection mechanisms.
Telecommunications
Android RAT deployment across 170 servers threatens telecom infrastructure security, mobile network integrity, and encrypted traffic protection for subscriber communications.
Information Technology/IT
Circulating RAT source code enables widespread command-and-control attacks against IT infrastructure, requiring enhanced egress security and zero trust segmentation controls.
Sources
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulateshttps://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.htmlVerified
- CVE-2024-43093: Google Android Privilege Escalation Flawhttps://www.sentinelone.com/vulnerability-database/cve-2024-43093/Verified
- CVE-2026-20428: Google Android Privilege Escalation Flawhttps://www.sentinelone.com/vulnerability-database/cve-2026-20428/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the malware's ability to escalate privileges, establish command and control channels, and exfiltrate sensitive data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF may have limited the malware's ability to communicate with unauthorized external servers, thereby reducing the likelihood of successful initial compromise.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation could have constrained the malware's ability to escalate privileges by enforcing strict access controls, thereby limiting unauthorized actions.
Control: East-West Traffic Security
Mitigation: While lateral movement was not observed, East-West Traffic Security could have limited any potential spread by enforcing strict workload-to-workload communication policies.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control could have limited the malware's ability to establish command and control channels by monitoring and restricting unauthorized outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement could have constrained the malware's data exfiltration efforts by enforcing strict outbound data policies.
The implementation of CNSF controls could have reduced the overall impact by limiting the malware's ability to escalate privileges, establish command channels, and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Mobile Application Security
- User Data Protection
- Financial Transactions
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of user payment credentials, keystrokes, and sensitive personal information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement application whitelisting to prevent unauthorized applications from executing.
- • Enforce least privilege access controls to limit the capabilities of applications and services.
- • Deploy network segmentation to isolate critical systems and limit the spread of malware.
- • Utilize intrusion detection and prevention systems to monitor and block malicious activities.
- • Conduct regular security awareness training to educate users on recognizing and avoiding phishing attempts.



