
Researchers have uncovered a fully-featured Android malware toolkit called Flying Eagle that was distributed through criminal Telegram channels and has now had its source code leaked publicly in a 388 MB archive nicknamed “Chinese Dragon.” The toolkit works as a drag-and-drop builder: an operator picks an app name, icon, decoy text, and command server address, and the system automatically generates a signed Android APK ready to deploy. Security researchers traced the toolkit’s infrastructure to 170 internet-connected servers carrying matching control panels and certificates — a level of distribution that signals significant criminal adoption.
In its initial wave, Flying Eagle was disguised as a fraudulent Chinese government app (“公安一网通办,” which translates roughly to “public security one-stop service”) distributed from a lookalike domain. The resulting malware can capture keystrokes during payment flows, record the screen, access the device camera, and display phishing prompts designed to steal login credentials and banking details. With the source code now circulating freely, security researchers warn that variants are likely to be repurposed for targets outside China, repackaged under different app names and disguises.
How to check if you’re affected
Affected devices are any Android phones or tablets that installed an app from an unofficial source that claimed to be a government or public security application, particularly if the app requested unusual permissions such as screen recording, accessibility access, or overlay permissions on other apps. Android users should only install apps from the official Google Play Store and the manufacturer’s pre-approved app store. If you believe you may have installed a fake government or banking app, remove it immediately, scan your device with a reputable mobile security app, and change passwords for any accounts accessed from that device.
