Find notable cyber news and cases, enriched with sources, timelines, and signals.

Flying Eagle Android RAT framework distribution through Telegram

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The Flying Eagle Android RAT framework is circulating through criminal Telegram channels, widening access to a kit that can steal payment passwords, log keystrokes, record screens, access cameras, and remotely control devices. The activity is tied to a fake 公安一网通办 Public Security app and targets Android users in China. Monitoring and certificate matches also point to a broader infrastructure footprint, raising the risk of more installations and operator reuse.

Related Happenings

Chinese authorities fraudulent Android app remediation advisory

Advisory/Mitigation
H score27 First: 29.07.2026 10:07 Last: 29.07.2026 10:07 Sources 1

How related: Chinese authorities advised anyone who installed the fraudulent application to remove it, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to police.

About this happening: Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control device...

RedWing Android spyware rented through Telegram

Malware Activity
H score21 First: 08.07.2026 18:30 Last: 08.07.2026 18:30 Sources 1

About this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

TrickMo Android banking malware adds TON-based covert command-and-control

Malware Activity
H score29 First: 11.05.2026 12:03 Last: 11.05.2026 12:03 Sources 1

About this happening: The TrickMo Android banking malware has added TON-based covert command-and-control, making its operator infrastructure harder to identify, block, or take down for victims...

Timeline

  1. 29.07.2026 10:07 1 articles · 1h ago

    National Cybersecurity Notification Center warns about fake 公安一网通办 app

    Initial Disclosure

    China's National Cybersecurity Notification Center warns that a fake “公安一网通办” Public Security service application distributed from 110gongan[.]com and associated with 207.56.30[.]188 can steal payment data and remotely control Android devices in China, and it advises affected users to remove the app, scan the device, change passwords, freeze payment channels if funds moved, and report the incident to police.

    Show sources
  2. 29.07.2026 10:07 2 articles · 1h ago

    Flying Eagle source code circulates through criminal Telegram channels

    Technical Analysis Update

    Researchers say Flying Eagle Android RAT source code is circulating through criminal Telegram channels, trace the framework to a fake “公安一网通办” Public Security service application targeting Android users in China, and match control panels, certificates, and telemetry to 170 internet servers. The code was distributed as a 388 MB archive called 中国龙.zip with a full Docker deployment, nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate.

    Show sources