Fake Public Security App Spreads Android RAT

The Hacker News · Medium sophistication
Last updated July 30, 2026

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was reportedly distributed from a lookalike website and could steal payment credentials and remotely control infected phones. The tooling is being shared in criminal Telegram channels, making it easier for more criminals to reuse the same scam-and-malware workflow.

How the attack worked

This campaign centered on a fake Android app impersonating a Public Security one-stop government service, known as 公安一网通办. Victims were directed to a lookalike website and prompted to download and install an APK, rather than obtaining the app from an official store or verified government domain. Once installed, the app requested high-risk permissions and used in-app phishing prompts to harvest payment credentials, keystrokes, screen content, and camera access. Behind the scenes, the app was built on the Flying Eagle Android RAT framework, giving attackers the ability to steal payment data and remotely control infected devices.

Why it succeeded

The pretext leaned on the authority of a government service, a category people are reluctant to ignore or question. Because the fake app was distributed from its own dedicated website rather than a marketplace with vetting controls, there was no app-store review process to catch it. The malware kit itself is also purpose-built for this kind of scam, with phishing prompts specifically designed for financial, adult-content, and government-service contexts, making the fraudulent prompts feel contextually normal to the victim.

Why this keeps scaling

A key finding is that Flying Eagle's source code is circulating in criminal Telegram channels, including groups observed distributing modified versions of the framework and even advertising cash-out services tied to stolen funds. This lowers the technical barrier for other criminals to launch similar scam-and-malware campaigns using the same workflow: build a convincing lookalike app, distribute it outside official channels, and harvest credentials through embedded phishing prompts.

What to watch for

  • Requests to install a mobile app from a website link instead of an official app store, especially for anything claiming to be a government service.
  • Apps that request unusually broad permissions, such as camera, keystroke, or screen-recording access, without clear justification.
  • In-app prompts asking for payment passwords or account credentials outside of a normal login flow.
  • Unfamiliar or slightly-off domain names hosting the app download.

How to build resistance

  • Treat any "must-install" mobile app request as suspicious unless it comes from an official app store or a verified government website.
  • Train employees and users to stop and report before entering payment details or passwords into any newly installed app.
  • If a suspicious app is found on a device, act quickly: remove it, scan the device, change affected passwords, and freeze payment channels if funds may have moved.
  • Reinforce awareness across finance, executive, and general mobile-user populations, since the pretext targets everyday services rather than a specific job function.

Key findings

  • Flying Eagle source code is circulating in criminal Telegram channels, lowering the barrier for copycat campaigns.
  • The framework was linked to a fake “公安一网通办” (Public Security) service app targeting Android users in China.
  • The fake app distribution infrastructure was reported as 110gongan[.]com (207.56.30[.]188).
  • The malware kit supports payment-password capture, keystroke capture, screen recording, camera access, and “phishing prompts” targeting finance, adult-content, and government-service apps.
  • Infrastructure fingerprints matching Flying Eagle were found on 170 servers, but that count does not directly translate to confirmed victims.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile users), Finance, Executives, IT/Helpdesk.
  • Affected industries: Government services, Financial services (payments), Consumers / mobile users.
  • Attack channels: website, telegram.
  • Impersonated: Public Security / government service portal (“公安一网通办”), Telegram channel operators offering “tools” and “cash-out services”.

Red flags to watch for

  • App is downloaded from a non-official website instead of an official app store or known government domain
  • Lookalike domain name and unusual hosting/IP
  • App requests high-risk permissions and shows in-app “phishing prompts”
  • Tooling distributed through criminal Telegram channels
  • Large archive claiming to include complete deployment and templates
  • Offers of “cash-out services” tied to financial theft
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Flying Eagle Android RAT?

Flying Eagle is a remote access trojan framework for Android whose source code circulates in criminal Telegram channels, lowering the barrier for copycat campaigns. It was linked to a fake Public Security service app targeting Android users in China.

How was the fake Public Security app distributed?

The malicious app was reportedly distributed from a lookalike website, 110gongan[.]com, associated with the IP 207.56.30[.]188, rather than an official app store or verified government domain.

What can this malware do once installed?

The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts targeting finance, adult-content, and government-service apps.

What should someone do if they installed the fake app?

Remove the app, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to authorities.

Read the video transcript

You see a site saying: “Important notice: install the ‘公安一网通办’ app to access Public Security services.” Looks official, right? But this “公安一网通办” APK from 110gongan.com hides the Flying Eagle Android RAT. Once installed, it can grab your payment passwords, record your screen, even turn on the camera. Here’s the trick: the app pops up fake in‑app prompts over your banking or government apps, asking for payment passwords and logins. You think you’re in your bank; you’re actually typing straight into Flying Eagle. Your move: if any “must‑install” government app isn’t from an official app store or a known government site, stop. Don’t install it, report the site or message to security.

Similar attacks

Telegram Dating Bot Used for Romance-to-Arson Scam

Telegram Dating Bot Used for Romance-to-Arson Scam

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations, clicking phishing links, and later carrying out arson or armed attacks. The alleged scheme started with romance-style outreach and payments via…

July 29, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026