China’s Cybercrime Scene Takes Flight with ‘Flying Eagle’ Malware Builder
A sophisticated malware-as-a-service (MaaS) platform has been uncovered in China, offering a one-stop-shop for cybercriminals to build and deploy mobile malware campaigns. Dubbed “Flying Eagle,” this full-service framework allows users to create infostealers that can drain victims’ bank accounts, making it a prime example of the evolving threat landscape in Asia.
The discovery was made by researchers at NetAskari and hunt.io, who stumbled upon Flying Eagle while investigating two IP addresses associated with a recent cybercrime campaign. The malicious operation involved fake apps masquerading as public safety services on Chinese social media platform WeChat, which promised citizens “one-stop handling” of online safety issues. Unsuspecting users who downloaded the apps unwittingly infected their mobile devices with information-stealing malware.
The investigation led to the uncovering of a substantial cybercriminal ecosystem built around Flying Eagle, a premium-grade MaaS builder that provides all the necessary infrastructure and features for hackers to launch their own mobile malware campaigns. What sets Flying Eagle apart is its distribution method – instead of being hosted on servers, it’s packaged as a Docker deployment, making it easily accessible and deployable by even the most novice cybercriminals.
Flying Eagle comes with a range of tools and features that cater to the needs of hackers, including Android Package Kit (APK) and software development kit (SDK) build tools, Java 11, Transport Layer Security (TLS) certificate, and phishing templates. The platform also offers a graphical user interface (GUI), clear workflows, and ready-to-deploy frameworks, making it accessible to ordinary cybercriminals rather than sophisticated hackers.
One of the most striking aspects of Flying Eagle is its ability to evade static detection out of the box. Researchers found that the APK builder conceals class names in its code, ensuring each new sample of malware is unique by replacing hardcoded package names with randomly generated but legitimate-sounding names. This level of sophistication demonstrates the evolving nature of cybercrime and the importance of staying vigilant.
Flying Eagle’s capabilities are alarming, to say the least. The malware can steal a wide variety of data from mobile devices, including payment credentials and screengrabs. It also supports keylogging and camera access, and can abuse accessibility services to escalate privileges and inject overlays into various apps.
The discovery of Flying Eagle serves as a stark reminder that cybercrime is becoming increasingly sophisticated and accessible. As the threat landscape continues to evolve, it’s essential for organizations and individuals to stay informed about emerging threats and take proactive measures to protect themselves against mobile malware attacks. By staying ahead of the curve, we can mitigate the risks associated with these types of threats.
To stay safe, users are advised to exercise caution when downloading apps from unknown sources and to keep their devices updated with the latest security patches. Additionally, organizations should prioritize mobile device management and implement robust security measures to detect and prevent malware attacks. By being proactive and informed, we can minimize the risks associated with these types of threats and stay one step ahead of cybercriminals like those behind Flying Eagle.
Source: Dark Reading — 2026-07-30