HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

‘Flying Eagle’ Mobile RAT‑as‑Service Enables Rapid Deployment of Banking‑Stealing Malware Across China

A China‑based Malware‑as‑a‑Service called “Flying Eagle” supplies turnkey mobile RATs that threat groups use to steal banking credentials and drain accounts. The threat highlights gaps in SOC 2 access‑control and endpoint‑security controls that continuous‑compliance programs must monitor.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
darkreading.com

‘Flying Eagle’ Mobile RAT‑as‑Service Enables Rapid Deployment of Banking‑Stealing Malware Across China

What Happened — A new Malware‑as‑a‑Service (MaaS) platform dubbed “Flying Eagle” is being operated out of China. The service provides a turnkey mobile Remote Access Trojan (RAT) builder that threat groups can customize and deploy to harvest credentials, capture screenshots, and exfiltrate banking data, ultimately draining victims’ accounts.

Why It Matters for Compliance & Audit Readiness

  • The scenario exemplifies a failure of logical‑access and endpoint‑security controls that SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) are designed to prevent and evidence.
  • Continuous monitoring of mobile device activity and evidence of policy enforcement are essential audit artifacts when a third‑party service can weaponize mobile endpoints.

Who Is Affected – Financial services, fintech, and any organization with mobile workforce or customer‑facing apps that handle payment credentials.

Recommended Actions

  • Map the RAT‑related risks to SOC 2 access‑control criteria (CC6.1, CC7.1) and verify that mobile device management (MDM) policies enforce least‑privilege, app‑allowlisting, and remote‑wipe capabilities.
  • Implement continuous endpoint‑telemetry collection and integrate alerts into your audit evidence repository to demonstrate ongoing control effectiveness.

Technical Notes – The service supplies pre‑packaged Android payloads that use native accessibility APIs to capture one‑time passwords and inject fraudulent transactions. No specific CVE is cited; the threat vector is malicious mobile malware delivered via phishing or compromised app stores. Source: Dark Reading

📰 Original Source
https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →