>samit_hota
Back to security news
SN-2026-238HighOpen

'Flying Eagle' Full-Service Mobile RAT Builder Spreads in China

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Android Users, Mobile Banking Applications
#news#malware#flying

A new Malware-as-a-Service (MaaS) platform known as the Flying Eagle mobile RAT builder is gaining traction among threat actors operating across China. Offered as a premium, full-service suite, the tool enables cybercriminals to generate customized mobile Remote Access Trojans (RATs) and infostealers without requiring advanced malware development expertise. Multiple distinct threat groups have already integrated the builder into their campaigns to execute targeted financial fraud.

How Flying Eagle Enables Account Takeover

Commercial mobile RAT builders simplify the process of weaponizing mobile endpoints by automating obfuscation, payload generation, and command-and-control (C2) communication setups. Flying Eagle focuses specifically on harvesting sensitive financial credentials and draining victims’ bank accounts.

Once an operator uses the builder to construct a customized implant, the malware is typically delivered through SMS phishing (smishing) campaigns, social engineering, or trojanized applications distributed via unofficial third-party app stores. Once installed on a victim’s device, this class of mobile infostealer relies heavily on abusing platform accessibility permissions to monitor user activity. Core features include keylogging, screen capturing, overlay attacks that place fake login forms over legitimate banking applications, and the interception of incoming SMS messages to capture two-factor authentication (2FA) passcodes. By combining stolen credentials with intercepted 2FA tokens, operators can initiate and authorize fraudulent bank transfers in real time.

Mitigation and Enterprise Risk

The adoption of the Flying Eagle malware framework across multiple threat groups significantly widens the blast radius, exposing both consumer banking customers and corporate environments—particularly organizations with permissive Bring Your Own Device (BYOD) policies.

To reduce exposure to Flying Eagle payloads, organizations should enforce strict Mobile Device Management (MDM) configurations that disable APK sideloading and restrict mobile installations strictly to official app repositories. Organizations should also deploy Mobile Threat Defense (MTD) agents to detect anomalous accessibility service grants, suspicious overlay activity, and unauthorized SMS monitoring on managed mobile endpoints.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call