Fake Public Security App Spreads Android RAT

The Hacker News · Medium sophistication
Last updated July 30, 2026

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was reportedly distributed from a lookalike website and could steal payment credentials and remotely control infected phones. The tooling is being shared in criminal Telegram channels, making it easier for more criminals to reuse the same scam-and-malware workflow.

How the attack worked

This campaign centered on a fake Android app impersonating a Public Security one-stop government service, known as 公安一网通办. Victims were directed to a lookalike website and prompted to download and install an APK, rather than obtaining the app from an official store or verified government domain. Once installed, the app requested high-risk permissions and used in-app phishing prompts to harvest payment credentials, keystrokes, screen content, and camera access. Behind the scenes, the app was built on the Flying Eagle Android RAT framework, giving attackers the ability to steal payment data and remotely control infected devices.

Why it succeeded

The pretext leaned on the authority of a government service, a category people are reluctant to ignore or question. Because the fake app was distributed from its own dedicated website rather than a marketplace with vetting controls, there was no app-store review process to catch it. The malware kit itself is also purpose-built for this kind of scam, with phishing prompts specifically designed for financial, adult-content, and government-service contexts, making the fraudulent prompts feel contextually normal to the victim.

Why this keeps scaling

A key finding is that Flying Eagle's source code is circulating in criminal Telegram channels, including groups observed distributing modified versions of the framework and even advertising cash-out services tied to stolen funds. This lowers the technical barrier for other criminals to launch similar scam-and-malware campaigns using the same workflow: build a convincing lookalike app, distribute it outside official channels, and harvest credentials through embedded phishing prompts.

What to watch for

  • Requests to install a mobile app from a website link instead of an official app store, especially for anything claiming to be a government service.
  • Apps that request unusually broad permissions, such as camera, keystroke, or screen-recording access, without clear justification.
  • In-app prompts asking for payment passwords or account credentials outside of a normal login flow.
  • Unfamiliar or slightly-off domain names hosting the app download.

How to build resistance

  • Treat any "must-install" mobile app request as suspicious unless it comes from an official app store or a verified government website.
  • Train employees and users to stop and report before entering payment details or passwords into any newly installed app.
  • If a suspicious app is found on a device, act quickly: remove it, scan the device, change affected passwords, and freeze payment channels if funds may have moved.
  • Reinforce awareness across finance, executive, and general mobile-user populations, since the pretext targets everyday services rather than a specific job function.

Key findings

  • Flying Eagle source code is circulating in criminal Telegram channels, lowering the barrier for copycat campaigns.
  • The framework was linked to a fake “公安一网通办” (Public Security) service app targeting Android users in China.
  • The fake app distribution infrastructure was reported as 110gongan[.]com (207.56.30[.]188).
  • The malware kit supports payment-password capture, keystroke capture, screen recording, camera access, and “phishing prompts” targeting finance, adult-content, and government-service apps.
  • Infrastructure fingerprints matching Flying Eagle were found on 170 servers, but that count does not directly translate to confirmed victims.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile users), Finance, Executives, IT/Helpdesk.
  • Affected industries: Government services, Financial services (payments), Consumers / mobile users.
  • Attack channels: website, telegram.
  • Impersonated: Public Security / government service portal (“公安一网通办”), Telegram channel operators offering “tools” and “cash-out services”.

Red flags to watch for

  • App is downloaded from a non-official website instead of an official app store or known government domain
  • Lookalike domain name and unusual hosting/IP
  • App requests high-risk permissions and shows in-app “phishing prompts”
  • Tooling distributed through criminal Telegram channels
  • Large archive claiming to include complete deployment and templates
  • Offers of “cash-out services” tied to financial theft
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Flying Eagle Android RAT?

Flying Eagle is a remote access trojan framework for Android whose source code circulates in criminal Telegram channels, lowering the barrier for copycat campaigns. It was linked to a fake Public Security service app targeting Android users in China.

How was the fake Public Security app distributed?

The malicious app was reportedly distributed from a lookalike website, 110gongan[.]com, associated with the IP 207.56.30[.]188, rather than an official app store or verified government domain.

What can this malware do once installed?

The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts targeting finance, adult-content, and government-service apps.

What should someone do if they installed the fake app?

Remove the app, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to authorities.

Read the video transcript

You see a site saying: “Important notice: install the ‘公安一网通办’ app to access Public Security services.” Looks official, right? But this “公安一网通办” APK from 110gongan.com hides the Flying Eagle Android RAT. Once installed, it can grab your payment passwords, record your screen, even turn on the camera. Here’s the trick: the app pops up fake in‑app prompts over your banking or government apps, asking for payment passwords and logins. You think you’re in your bank; you’re actually typing straight into Flying Eagle. Your move: if any “must‑install” government app isn’t from an official app store or a known government site, stop. Don’t install it, report the site or message to security.

Similar attacks

LogoKit Builds Real-Time Fake Login Pages

LogoKit Builds Real-Time Fake Login Pages

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

July 29, 2026