
Telegram Dating Bot Used for Romance-to-Arson Scam
Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…
Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was reportedly distributed from a lookalike website and could steal payment credentials and remotely control infected phones. The tooling is being shared in criminal Telegram channels, making it easier for more criminals to reuse the same scam-and-malware workflow.
This campaign centered on a fake Android app impersonating a Public Security one-stop government service, known as 公安一网通办. Victims were directed to a lookalike website and prompted to download and install an APK, rather than obtaining the app from an official store or verified government domain. Once installed, the app requested high-risk permissions and used in-app phishing prompts to harvest payment credentials, keystrokes, screen content, and camera access. Behind the scenes, the app was built on the Flying Eagle Android RAT framework, giving attackers the ability to steal payment data and remotely control infected devices.
The pretext leaned on the authority of a government service, a category people are reluctant to ignore or question. Because the fake app was distributed from its own dedicated website rather than a marketplace with vetting controls, there was no app-store review process to catch it. The malware kit itself is also purpose-built for this kind of scam, with phishing prompts specifically designed for financial, adult-content, and government-service contexts, making the fraudulent prompts feel contextually normal to the victim.
A key finding is that Flying Eagle's source code is circulating in criminal Telegram channels, including groups observed distributing modified versions of the framework and even advertising cash-out services tied to stolen funds. This lowers the technical barrier for other criminals to launch similar scam-and-malware campaigns using the same workflow: build a convincing lookalike app, distribute it outside official channels, and harvest credentials through embedded phishing prompts.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Flying Eagle is a remote access trojan framework for Android whose source code circulates in criminal Telegram channels, lowering the barrier for copycat campaigns. It was linked to a fake Public Security service app targeting Android users in China.
The malicious app was reportedly distributed from a lookalike website, 110gongan[.]com, associated with the IP 207.56.30[.]188, rather than an official app store or verified government domain.
The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts targeting finance, adult-content, and government-service apps.
Remove the app, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to authorities.
You see a site saying: “Important notice: install the ‘公安一网通办’ app to access Public Security services.” Looks official, right? But this “公安一网通办” APK from 110gongan.com hides the Flying Eagle Android RAT. Once installed, it can grab your payment passwords, record your screen, even turn on the camera. Here’s the trick: the app pops up fake in‑app prompts over your banking or government apps, asking for payment passwords and logins. You think you’re in your bank; you’re actually typing straight into Flying Eagle. Your move: if any “must‑install” government app isn’t from an official app store or a known government site, stop. Don’t install it, report the site or message to security.

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…