Flying Eagle Android Spyware Kit Leaks Onto Telegram, Traced to 170 Servers

Researchers link the free-to-copy surveillance toolkit to a fake Chinese police services app aimed at Android phone users.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge overhead photoreal shot of a generic black smartphone on a dark slate surface, screen glowing faint blue with abstract geometric lock-pa
Share

Key points

  • Source code for the Flying Eagle Android remote access tool is being shared through criminal Telegram channels, opening the door for copycat versions.
  • Threat intelligence firm Hunt.io and independent researcher NetAskari matched control panels and TLS certificates to 170 internet-facing servers running the framework.
  • The kit has been used to build a fake "公安一网通办" (Public Security One-Network Service) app aimed at Android users in mainland China.
  • Flying Eagle can steal payment passwords, giving operators a path to victims' money as well as their data.

A piece of Android spyware called Flying Eagle is spreading fast, and researchers say the reason is simple: someone put the source code up for grabs.

The code is circulating in criminal Telegram groups, which means anyone with modest skills can now spin up their own version. Think of it as a burglary kit passed around a chat room.

Flying Eagle is what security people call a remote access trojan, or RAT: malicious software that hides on a phone and lets an outside operator read messages, watch what you type, and pull files off the device. On Android, that reach can include banking apps.

Who is being targeted?

For now, Android users in China. The researchers tied Flying Eagle to a fake app dressed up as "公安一网通办", a real Public Security service that Chinese citizens use for government paperwork. Victims think they are logging into an official portal. Instead, they are handing a stranger the keys to their phone.

The kit specifically supports capturing payment passwords, the short codes people type to approve transfers inside apps like WeChat Pay and Alipay. That turns the spyware from a surveillance nuisance into a direct route to someone's savings.

How did researchers find it?

Hunt.io, working with independent researcher NetAskari, went hunting for the servers that run Flying Eagle's back end. Every RAT needs a command panel, the web dashboard an operator uses to see infected phones and issue instructions.

By fingerprinting the look of that panel and the digital certificates it presents, the team matched 170 internet-facing servers to the same framework. The Hacker News first surfaced the wider write-up. That is a large footprint for a tool most people had not heard of a month ago.

Detail Figure
Servers identified 170
Primary target region China (Android)
Disguise used Fake "公安一网通办" police services app
Code availability Shared via criminal Telegram channels
Notable capability Payment-password theft

What should ordinary phone users do?

Stick to official app stores and check the developer name before you install anything. Government services in China are distributed through recognised channels, not links pushed in chat apps or SMS.

Be wary of any app that asks for Accessibility permissions on Android. That single setting is what lets tools like Flying Eagle read your screen and type on your behalf. If a "government" app requests it, that is a red flag.

If you think you installed something dodgy, uninstall it, change your banking and wallet passwords from a different device, and call your bank's fraud line. Do not wait to see what happens.

Why this matters beyond China

Leaked RAT code rarely stays in one country. Once a working framework is free, other groups rebrand it, swap out the fake app, and point it at new victims. The same skeleton that impersonates a Chinese police portal today can impersonate a European tax office or a US delivery service next quarter.

Security teams should add the 170 servers to their blocklists and watch for the certificate patterns Hunt.io published. Everyone else should treat unexpected app-install prompts with the same suspicion as a stranger asking for their PIN.

© 2026 Threat Vectr