🟠 High | Source: The Hacker News
The source code for Flying Eagle, an Android remote access trojan (RAT) framework, is being shared across criminal Telegram channels, enabling wider adoption by threat actors. Researchers have identified infrastructure linked to the framework across 170 internet-facing servers, with the RAT disguised as a Chinese government public security app to harvest payment credentials and passwords. The broad distribution of the source code significantly lowers the barrier to entry for attackers seeking to deploy this toolkit.
Security Architect’s Take: Organisations managing mobile device fleets or BYOD programmes should ensure mobile threat defence (MTD) solutions are deployed and capable of detecting sideloaded applications impersonating government or enterprise services. Review app allowlisting policies and consider blocking known malicious C2 infrastructure indicators from the Hunt.io and NetAskari reports at your network perimeter and cloud egress points.
Original advisory: Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates