Android RAT Infrastructure Reveals Large-Scale Mobile Surveillance Campaign
ID: c0faddc4-f996-5cf8-8694-06de4b3d7c3f
STIX ID: report--c0faddc4-f996-5cf8-8694-06de4b3d7c3f
Feed Name: Zimperium Blog
Threat Score
The investigation uncovered infrastructure supporting the 'Flying Eagle' Android remote access trojan, identifying over 170 command-and-control servers linked to a campaign that enables surveillance, data theft, and remote command execution on compromised devices; the scale suggests a coordinated, multi-region operation and highlights the need for behavior-based mobile threat detection, trusted app installation practices, and continuous monitoring for suspicious device activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
