Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Overview
The source code for the Flying Eagle Android remote access trojan (RAT) has been found circulating in criminal Telegram channels, raising concerns about potential exploitation. Researchers from Hunt.io and NetAskari traced this malicious framework to 170 internet servers, linking it to a deceptive application masquerading as a Chinese Public Security service. This application targets Android users in China and reportedly supports functionalities related to payment passwords. The distribution of this RAT poses significant risks to users, as it can enable attackers to gain unauthorized control over devices, potentially leading to data theft and financial fraud. Users in China, particularly those using the compromised app, should be vigilant and avoid downloading unverified applications to protect their personal information.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Android devices, specifically those downloading the fake '公安一网通办' Public Security service application.
- Action Required: Users should avoid downloading applications from untrusted sources and ensure their devices have up-to-date security software.
- Timeline: Newly disclosed
Original Article Summary
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
Impact
Android devices, specifically those downloading the fake '公安一网通办' Public Security service application.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should avoid downloading applications from untrusted sources and ensure their devices have up-to-date security software.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Android, Google, Malware, and 1 more.