Dateline: July 30, 2026
A Leaked Phone-Hacking Kit Is Turning Amateurs Into Bank Thieves
You don’t need to be a skilled hacker anymore to hack someone’s phone and empty their bank app. A leaked malware kit now does the hard part for you. Researchers found it running on 170 servers, and a newer, nastier version is already taking flight.
What Happened?
Security researchers traced a full-service Android malware builder called Flying Eagle spreading across the Chinese cybercrime world. It started with a fake app. In June, Chinese authorities warned the public about a phony government service app that promised to handle public safety matters online. Anyone who installed it infected their own phone with data-stealing malware.
Two researchers followed the trail from that warning. What they found was a whole criminal supply chain built around one tool. Flying Eagle packs everything a would-be crook needs into a single kit. It builds the malicious app, hides it from antivirus, and runs a control panel to manage infected phones.
No real skill required. The whole thing ships as a ready-to-run package with build tools and fake app templates that copy TikTok, adult sites, financial apps, and government services.
Here is where it gets worse. The source code was stolen early this year, along with close to 200 customer databases. Once it leaked, patched copies started circulating through Telegram channels that sell the tool, offer tech support, and run cash-out services that take a 20 to 50 percent cut of stolen funds. Researchers counted 170 servers running the framework.
Then a successor showed up. In late June, one of those channels released a newer kit called Night Dragon. It captures live screens, microphone audio, and camera feeds. It reads text messages and photos. It fakes a black system update screen to hide the crook’s activity while they work. Version 2 is already in development.
What’s the Impact?
The malware goes straight for money. It steals payment passwords, logs keystrokes, grabs screenshots, and drops fake login screens over real banking and crypto apps. It abuses Android’s accessibility features to grant itself more control. Target apps include major banks and popular wallets.
The bigger worry is the trend. This is malware-as-a-service, and it has lowered the bar to almost nothing. Point-and-click panels and prebuilt phishing templates mean ordinary criminals, not just skilled hackers, can now launch these campaigns. For now the victims are mostly in China, but researchers noted the kits include templates aimed at other countries. Tools like these rarely stay put.
How to Avoid This
Only install apps from official stores. Real government agencies and banks do not send apps through text links or random websites.
- Be suspicious of any app that asks for accessibility permissions. That setting is a favorite target, and few normal apps truly need it.
- Watch for phones that behave oddly, like sudden battery drain, a hidden or missing app icon, or a screen that freezes on a fake update.
- Keep the phone’s built-in protection turned on, and check app permissions often. Pull anything you do not recognize.
- For security teams, the indicators below can help you hunt for this infrastructure and block it before it reaches your people.