Threat Actor ๐Ÿ‡จ๐Ÿ‡ณ China

Night Dragon

Also known as: G0014

Indicators of Compromise 36

MITRE ATT&CK TTPs 7

Source Articles

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
The article details the discovery and analysis of a malicious Android Remote Access Tool (RAT) framework called Flying Eagle, which was leaked in early 2026 and has since been widely distributed by cybercriminal actors. The malware is distributed via fake apps impersonating Chinese government services and includes capabilities for credential theft, keylogging, screen capture, and phishing overlays. At least 170 active servers hosting the Flying Eagle infrastructure were identified, primarily in Hong Kong, using shared codebases and panel fingerprints. A new successor platform named Night Dragon has emerged, developed by the threat actor behind the @SQLRCE0 Telegram channel, indicating ongoing evolution of this mobile threat ecosystem.
static-urls
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The source code for the Flying Eagle Android remote access trojan (RAT) is circulating in criminal Telegram channels, enabling widespread deployment of the malware. Researchers identified infrastructure linked to 170 servers hosting control panels or certificates associated with the RAT, which is used in a fake Chinese Public Security app called 'ๅ…ฌๅฎ‰ไธ€็ฝ‘้€šๅŠž'. The malware can steal payment credentials, record screens, access cameras, and perform phishing attacks on financial and government apps. A second Android RAT, Night Dragon, was introduced by one of the same Telegram groups, though it appears to be a separate build with no shared code with Flying Eagle.
hacker-news ยท1mo ago