Public Android RAT Builder Expands China Credential Theft
The risk is no longer one fake app. A public Android RAT builder lets copycats spin up new lures fast, so defenders are facing a reusable fraud kit, not a single sample. That lowers the bar for credential and payment theft against Android users who trust government or service apps.
Researchers tied Flying Eagle’s control infrastructure to 170 internet servers and linked it to a fake 公安一网通办 app targeting users in China. The builder can swap in an app name, icon, lure text, and command server, then produce a signed Android app that captures passwords, keystrokes, screen activity, and camera access.
The broader problem is scale and reuse. Once the builder circulates publicly, the same framework can be re-skinned for new lures and redeployed quickly across finance and government-facing users.