Flying Eagle Mobile RAT Drains Bank Accounts in Chinese MaaS Scheme
A sophisticated mobile remote access trojan (RAT) builder dubbed ‘Flying Eagle’ has emerged as a premium offering in China’s bustling malware-as-a-service (MaaS) underground, attracting multiple financially motivated threat groups with its full-service infection kit. The builder packages together Android-targeting payloads, command-and-control infrastructure, and post-exploitation tooling designed specifically to harvest mobile banking credentials and siphon funds from victim accounts in real time. Researchers tracking the campaign note that subscriptions to Flying Eagle rival those of established Western MaaS kits, signaling a maturing and increasingly commercialized mobile threat ecosystem across East Asia.
Flying Eagle operators provide subscribers with a modular RAT capable of overlay attacks, SMS interception, keylogging, and accessibility-service abuse—techniques that allow attackers to bypass two-factor authentication prompts sent via SMS and silently authorize fraudulent transfers. The trojan is typically distributed through smishing campaigns, malicious app stores, and trojanized APKs disguised as legitimate banking, shopping, or government applications. Once installed, it establishes persistence, exfiltrates device metadata, and waits for the victim to launch a targeted banking app, at which point it overlays a convincing phishing screen to harvest credentials and one-time passcodes. Stolen credentials often surface on Chinese-language dark web forums within hours of compromise, where they feed into downstream fraud operations.
At least three distinct threat clusters—including groups tracked internally as GoldDigger, DoubleFinger, and the long-running FakeMoney syndicate—have adopted Flying Eagle in active campaigns against retail banking customers across mainland China, Hong Kong, and Taiwan. Intelligence suggests the developer maintains a tiered pricing model with premium customers receiving access to stealthier payload variants, anti-analysis obfuscation, and dedicated C2 servers geofenced to specific financial institutions. Researchers assess with high confidence that the builder’s authors operate from within China and reinvest profits into expanding the platform’s evasion capabilities, including dynamic APK packing and abuse of legitimate cloud services for command relay.
Defenders and consumers should treat unsolicited mobile app installations as high risk, particularly those promoted via SMS links, WeChat messages, or third-party app stores. Organizations operating in the financial sector are advised to deploy mobile threat defense solutions, enforce certificate pinning, and monitor for accessibility-service anomalies on managed Android devices. Individuals concerned about credential exposure from prior mobile banking incidents can verify their accounts using our email breach checker, test whether their device traffic is leaking identifying data with our DNS leak test, and audit saved credentials against known leaks using our password checker.