'Flying Eagle' Full-Service Mobile RAT Builder Spreads in China
- CVE ID
- N/A
- Affected Products / Orgs
- Android Users, Mobile Banking Applications
A new Malware-as-a-Service (MaaS) platform known as the Flying Eagle mobile RAT builder is gaining traction among threat actors operating across China. Offered as a premium, full-service suite, the tool enables cybercriminals to generate customized mobile Remote Access Trojans (RATs) and infostealers without requiring advanced malware development expertise. Multiple distinct threat groups have already integrated the builder into their campaigns to execute targeted financial fraud.
How Flying Eagle Enables Account Takeover
Commercial mobile RAT builders simplify the process of weaponizing mobile endpoints by automating obfuscation, payload generation, and command-and-control (C2) communication setups. Flying Eagle focuses specifically on harvesting sensitive financial credentials and draining victims’ bank accounts.
Once an operator uses the builder to construct a customized implant, the malware is typically delivered through SMS phishing (smishing) campaigns, social engineering, or trojanized applications distributed via unofficial third-party app stores. Once installed on a victim’s device, this class of mobile infostealer relies heavily on abusing platform accessibility permissions to monitor user activity. Core features include keylogging, screen capturing, overlay attacks that place fake login forms over legitimate banking applications, and the interception of incoming SMS messages to capture two-factor authentication (2FA) passcodes. By combining stolen credentials with intercepted 2FA tokens, operators can initiate and authorize fraudulent bank transfers in real time.
Mitigation and Enterprise Risk
The adoption of the Flying Eagle malware framework across multiple threat groups significantly widens the blast radius, exposing both consumer banking customers and corporate environments—particularly organizations with permissive Bring Your Own Device (BYOD) policies.
To reduce exposure to Flying Eagle payloads, organizations should enforce strict Mobile Device Management (MDM) configurations that disable APK sideloading and restrict mobile installations strictly to official app repositories. Organizations should also deploy Mobile Threat Defense (MTD) agents to detect anomalous accessibility service grants, suspicious overlay activity, and unauthorized SMS monitoring on managed mobile endpoints.
Related content
Inside the Splintered Underground Market of the BTMOB Android RAT
Security NewsGoldDigger Android Banking Trojan Poses Evolving Mobile Threat
Security NewsMicrosoft Warns of Global Surge in ACR Stealer Malware Attacks
Security NewsAnMed Health System Halts Operations Across SC and GA After Malware Attack
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call