# Flying Eagle: The Rising Threat of Mobile Malware from China

*Published July 31, 2026*
*Source: [https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china](https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china)*

## Executive Summary

Chinese cybercriminals are using a powerful malware builder called Flying Eagle to target finance apps, leading to widespread data theft. The ease of access and sophisticated evasion techniques make this malware-as-a-service a significant threat.

## Article

Chinese cybercriminals have been leveraging sophisticated mobile malware frameworks to target finance apps, leading to substantial illicit financial gains. On June 18, China's National Cybersecurity Reporting Center issued a warning on WeChat, alerting the public about a fake app posing as a provincial public security service. This app, promising convenient handling of public safety matters, infected devices with information-stealing malware upon download. The warning identified two IP addresses linked to this malicious campaign.

Investigations by independent researcher NetAskari and hunt.io uncovered an extensive cybercriminal ecosystem anchored by 'Flying Eagle,' a robust malware-as-a-service builder. Flying Eagle provides all necessary tools for creating mobile malware campaigns, packaged as a complete Docker deployment. This setup includes a web server, WebSocket server, PHP, MySQL, and more, making it accessible for even novice cybercriminals.

The service comes equipped with APK and SDK build tools, Java 11, a default TLS certificate, and various phishing templates. These templates imitate popular platforms like TikTok and financial apps. Researchers noted the ease and modularity of these modern MaaS offerings, which feature user-friendly interfaces and workflows. Flying Eagle's APK builder incorporates advanced evasion techniques to avoid detection by antivirus software, ensuring each malware sample appears unique.

Originally confined to closed circles, Flying Eagle has recently spread through the Chinese cybercriminal community. A Telegram channel named 'SQLRCE0' has emerged, distributing the tool for $2,000 in Tether cryptocurrency and providing technical support. Although a newer tool, 'Night Dragon,' has been introduced, Flying Eagle remains prevalent, with hundreds of active servers identified. Both tools demonstrate advanced capabilities, including data theft, keylogging, and camera access, posing a significant threat to users of popular finance apps and government services.
