Fake China Police App Tied to Android RAT Ring

Security Affairs · High sophistication
Last updated July 31, 2026

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal credentials through in-app “overlay” login prompts targeting payment, banking, and government service apps.

Key findings

  • Investigation began with a “fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service,” then expanded to a larger ecosystem using the leaked Flying Eagle Android RAT framework.
  • Researchers mapped “170 active servers” running the framework and found “two Telegram channels distributing modified versions of the stolen codebase.”
  • The builder supports creating lured APKs by letting operators choose “lured text, application names, icons, and C2 callback addresses,” enabling believable fake apps.
  • The malware ecosystem includes phishing overlays targeting “financial, adult, and government service apps,” and a newer successor called “Night Dragon” with features to hide activity (black-screen fake updates, icon hiding) and one-click credential overlays for major payment/bank/crypto apps.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile device users), Finance and payments teams, Executives and admins with high-value accounts, Anyone using mobile banking/crypto wallet apps.
  • Affected industries: Finance / payments, Banking, Government services, Cryptocurrency / wallets.
  • Attack channels: website.
  • Impersonated: Chinese Provincial Public Security Bureau (government service).

Awareness takeaways

  • Treat “official” mobile apps delivered by direct download links (APKs) as high risk; prefer official app stores and verified publisher names.
  • Be cautious of government/public-safety themed apps or messages that push you to install software, criminals use authority-themed impersonation to boost compliance.
  • Watch for fake login screens inside apps (overlay prompts) asking for payment/bank credentials; stop and verify before entering passwords.

Red flags to watch for

  • App is delivered as a downloadable APK (not via an official app store)
  • The app impersonates a government service to create urgency and trust
  • After installation, the app shows login prompts/overlays for financial apps (credential capture)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a site saying, “Download the official Provincial Public Security Bureau service app” for Android. Looks like a real police portal, right? Behind that APK could be the Flying Eagle Android RAT. Criminals use it to build fake police and welfare apps, complete with copied icons and text, all controlled from one of over 170 known servers. Once installed, it can pop up perfect-looking overlays on top of your banking or payment apps. You think you’re logging into your bank, but you’re handing credentials straight to their Night Dragon successor. Your move: if an 'official' app comes as an APK download link, skip it. Only install government or banking apps from the official app store with the verified publisher name.

Similar attacks

Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

July 29, 2026
Fake Public Security App Spreads Android RAT

Fake Public Security App Spreads Android RAT

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was…

July 29, 2026