{"id":398719,"date":"2026-08-02T04:06:54","date_gmt":"2026-08-02T04:06:54","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=398719"},"modified":"2026-08-02T04:06:54","modified_gmt":"2026-08-02T04:06:54","slug":"flying-eagle-rat-on-android-how-the-fake-app-records-screens-and-steals-logins","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/flying-eagle-rat-on-android-how-the-fake-app-records-screens-and-steals-logins\/","title":{"rendered":"Flying Eagle RAT on Android: How the Fake App Records Screens and Steals Logins"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A harmless-looking Android app can become a window into everything happening on the phone. Flying Eagle gives criminals the tools to record screens, capture passwords and remotely operate a device after one deceptive installation.<\/p><div id=\"mwtad650682435\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The threat is not tied to a single app name or icon. Attackers can repackage Flying Eagle with a new disguise for each campaign, making the installation source, permissions and behavior far more important than its appearance.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/flying-eagle-android-rat.png\" alt=\"Flying Eagle Android RAT stealing credentials through a disguised mobile app\" class=\"wp-image-398711\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/flying-eagle-android-rat.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/flying-eagle-android-rat-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/flying-eagle-android-rat-1024x683.png 1024w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Flying Eagle is packaged as a customized Android app that abuses powerful permissions to record screens, steal credentials and receive remote commands.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad3505238388\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle is a commercial Android remote access trojan distributed as a complete criminal toolkit. Its buyers do not need to build an operation from scratch: the package includes source code, server components, a web control panel, app-building tools and templates that can be adapted to different lures.<\/p><div id=\"mwtad2701407013\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">An operator can choose the malicious app&#8217;s visible name, icon and story before generating a signed APK. The result may look like a government service, security tool, financial app or ordinary utility. Behind that changing exterior, the app attempts to obtain Android Accessibility access and other sensitive permissions that allow it to observe and control the device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accessibility abuse is central to the attack. Flying Eagle can use the service to monitor interface content, simulate gestures and interact with apps. It also supports screen recording, keylogging and counterfeit overlays that appear above legitimate login pages. A victim can type a banking password into what looks like the correct app while the information is actually sent to a criminal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The toolkit is designed to help individual builds evade simple detection. It can randomize package and class names, encrypt the address of its command server and add bulky, low-information data to change the app&#8217;s size and appearance. Those changes do not make the program legitimate; they make repeated samples harder to match using basic signatures.<\/p><div id=\"mwtad658147798\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle has been disguised as official-looking Android software and distributed through deceptive websites, private messaging channels and other unofficial sources. The malicious app does not need to break into a phone remotely. It relies on the victim enabling installation from an unknown source and approving the permissions presented after launch.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Threat type: Android remote access trojan and credential stealer<\/li><li>Delivery: customized APK files distributed outside official app stores<\/li><li>Core techniques: Accessibility abuse, screen recording, keylogging and fake overlays<\/li><li>Operator tools: web panel, app builder and configurable command server<\/li><li>Primary danger: account takeover, payment fraud and loss of private data<\/li><\/ul>\n\n\n\n<div id=\"mwtad1896438418\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How the Flying Eagle Android RAT Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: A criminal creates a customized fake app<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle includes tools that let an operator select the app name, icon, package details and server address. This allows the same malware to be reused under many convincing identities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A campaign can imitate an institution or build a generic utility that fits the message being sent. The polished appearance is part of the lure and does not show who actually developed the underlying code.<\/p><div id=\"mwtad3226573362\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: The APK is promoted outside an official store<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Victims are directed to a third-party webpage, Telegram channel, text-message link or another unofficial download source. The instructions may tell them to permit installations from the current browser or messaging app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One observed disguise imitated a Chinese public-security application, but that is only one example. A different operator can replace the branding without changing the malicious behavior.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: The app asks for Accessibility and other permissions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After installation, the fake app requests access that greatly exceeds what its claimed purpose needs. Accessibility Services can give it visibility into screen content and the ability to simulate taps and swipes.<\/p><div id=\"mwtad1005076339\" class=\"gas_fallback-ad_381404-ad_309691-placement_381406\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Additional permissions may expose files, notifications, camera or microphone functions. The prompts can be wrapped in an activation, identity-verification or update story to make approval seem necessary.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: The device connects to the attacker&#8217;s panel<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The app decrypts its configured command-server address and contacts the operator&#8217;s infrastructure. Device details and connection status are then made available through a web panel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Encrypted configuration and randomized code help each malicious build look different, but the purpose remains the same: establish a channel through which the operator can monitor and control the phone.<\/p><div id=\"mwtad3586261234\" class=\"gas_fallback-ad_360582-ad_309691-placement_360581\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: Screens, keystrokes and credentials are collected<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle can record the display and log information entered by the victim. Fake overlays can reproduce login screens for banking, payment or government apps and send the submitted credentials to the attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Screen access can reveal balances, private conversations, one-time codes and recovery information even when a particular app is not directly targeted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6: The attacker expands the compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Stolen email and financial credentials can be used on other devices, while remote-control functions let the operator alter settings or gather more information from the phone. Contacts may also receive new malicious links from an account that now appears familiar.<\/p><div id=\"mwtad2338252112\" class=\"gas_fallback-ad_360567-ad_309691-placement_360771\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A successful infection can therefore continue after the APK is removed unless compromised passwords, sessions and recovery methods are also replaced.<\/p>\n\n\n\n<div id=\"mwtad1568757070\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Why Flying Eagle Is More Than a Single Malicious App<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle should be understood as a toolkit. Different criminals can deploy it with different icons, domains and stories, so a list of known filenames will never be complete.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The builder changes visible app branding for each lure<\/li><li>Randomized package and class names complicate simple matching<\/li><li>Encrypted server configuration hides the destination from casual inspection<\/li><li>A ready-made control panel lowers the skill needed to operate the malware<\/li><li>Phishing templates and server components support full campaigns<\/li><li>Source-code access allows criminals to modify future versions<\/li><\/ul>\n\n\n\n<div id=\"mwtad1637900808\" class=\"gas_fallback-ad_318930-ad_309691-placement_360589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Warning Signs on an Android Phone<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>An app was installed from a link rather than an official store<\/li><li>A simple utility requests Accessibility or device-administrator access<\/li><li>Banking or government apps display unusual login panels<\/li><li>The screen activates, changes or records without a clear reason<\/li><li>The camera or microphone indicator appears unexpectedly<\/li><li>A newly installed app vanishes or has a blank icon<\/li><li>Battery, processor or mobile-data use increases sharply<\/li><li>Security settings change or permission prompts return repeatedly<\/li><\/ul>\n\n\n\n<div id=\"mwtad3350567686\" class=\"gas_fallback-ad_381388-ad_309691-placement_381390\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What to Do If You Installed a Flying Eagle App<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Take the phone offline<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable airplane mode, then make sure Wi-Fi and Bluetooth are off. This interrupts the live connection and limits the attacker&#8217;s opportunity to issue more commands while you clean the device.<\/p><div id=\"mwtad1634315656\" class=\"gas_fallback-ad_360571-ad_309691-placement_360772\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Do not open banking, email or password-manager apps on the suspected phone. Use another trusted device for urgent account protection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Check and revoke special access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In Android Settings, review Accessibility, Device admin apps, notification access, VPN settings and permission to install unknown apps. Disable the suspicious app wherever it appears.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the app prevents changes, restart into Safe Mode. Third-party applications normally remain inactive there, which can make it possible to revoke administrator rights and uninstall the package.<\/p><div id=\"mwtad3977039184\" class=\"gas_fallback-ad_360576-ad_309691-placement_360773\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6594472392\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Remove the app and its installer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the full Apps list in Settings and sort by recently installed where possible. Do not rely on the launcher, because malicious packages can hide their icons. Uninstall the suspicious entry and delete its APK from Downloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Turn off unknown-app installation for the browser, messenger or file manager involved. That prevents the same route from silently being reused.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Run a mobile malware scan<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Scan the phone for remaining components and other malicious packages that may have arrived through the same source.<\/p><div id=\"mwtad949180748\" class=\"gas_fallback-ad_360583-ad_309691-placement_360774\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8849826992\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n<p>Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don&#8217;t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.<\/p>\n\n\n<ol class=\"wp-block-list\">\n<li>\n<p class=\"mwt_quick_overview\">Download Malwarebytes for Android.<\/p>\n<p>You can download <strong>Malwarebytes for Android<\/strong> by clicking the link below.<\/p>\n<figure><img decoding=\"async\" class=\"alignleft size-full wp-image-81150 mwt_product_icon_logo\" title=\"Malwarebytes Icon\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2018\/06\/Malwarebytes-LOGO.png\" alt=\"Malwarebytes Logo\" width=\"40\" height=\"40\"\/><\/figure><div class=\"mwt_download_box\"><strong><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware&#038;hl=en\" target=\"_blank\" rel=\"noopener noreferrer\">MALWAREBYTES FOR ANDROID DOWNLOAD LINK<\/a><\/strong><br \/><em>(The above link will open a new page from where you can download Malwarebytes for Android)<\/em><\/div>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Install Malwarebytes for Android on your phone.<\/p>\n<p>In the Google Play Store, tap &#8220;<strong>Install<\/strong>&#8221; to install Malwarebytes for Android on your device.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106940\" title=\"Tap Install to install Malwarebytes for Android\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App.jpg\" alt=\"Tap Install to install Malwarebytes for Android\" width=\"292\" height=\"580\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/figure><p><\/p>\n<p>When the installation process has finished, tap &#8220;<strong>Open<\/strong>&#8221; to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106941\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App.jpg\" alt=\"Malwarebytes for Android - Open App\" width=\"292\" height=\"578\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App-152x300.jpg 152w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Follow the on-screen prompts to complete the setup process<\/p>\n<p>When Malwarebytes will open, you will see the <em>Malwarebytes Setup Wizard<\/em> which will guide you through a series of permissions and other setup options.<br \/>This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106944\" title=\"Malwarebytes Setup Screen 1\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1.jpg\" alt=\"Malwarebytes Setup Screen 1\" width=\"292\" height=\"577\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1-152x300.jpg 152w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Tap on &#8220;<strong>Got it<\/strong>&#8221; to proceed to the next step.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106945\" title=\"Malwarebytes Setup Screen 2\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2.jpg\" alt=\"Malwarebytes Setup Screen 2\" width=\"292\" height=\"580\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on &#8220;<strong>Give permission<\/strong>&#8221; to continue.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106946\" title=\"Malwarebytes Setup Screen 3\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3.jpg\" alt=\"Malwarebytes Setup Screen 3\" width=\"292\" height=\"570\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3-154x300.jpg 154w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Tap on &#8220;Allow&#8221; to permit Malwarebytes to access the files on your phone.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106947\" title=\"Malwarebytes Setup Screen 4\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7.jpg\" alt=\"Malwarebytes Setup Screen 4\" width=\"292\" height=\"573\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7-153x300.jpg 153w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Update database and run a scan with Malwarebytes for Android<\/p>\n<p>You will now be prompted to update the Malwarebytes database and run a full system scan.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106939\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues.jpg\" alt=\"Malwarebytes fix issue\" width=\"292\" height=\"579\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/figure><p><\/p>\n<p>Click on &#8220;<strong>Update database<\/strong>&#8221; to update the Malwarebytes for Android definitions to the latest version, then click on &#8220;<strong>Run full scan<\/strong>&#8221; to perform a system scan.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106948\" title=\"Update database and run Malwarebytes scan\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan.jpg\" alt=\"Update database and run Malwarebytes scan on phone\" width=\"291\" height=\"575\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan.jpg 291w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan-152x300.jpg 152w\" sizes=\"(max-width: 291px) 100vw, 291px\" \/><\/figure><p><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Wait for the Malwarebytes scan to complete.<\/p>\n<p>Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106943\" title=\"Malwarebytes scanning phone for malware\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware.jpg\" alt=\"Malwarebytes scanning Android for Vmalware\" width=\"292\" height=\"579\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Click on &#8220;Remove Selected&#8221;.<\/p>\n<p>When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the &#8220;<strong>Remove Selected<\/strong>&#8221; button.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106942\" title=\"Tap on the Remove button to get rid of malware\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware.jpg\" alt=\"Remove malware from your phone\" width=\"760\" height=\"600\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware.jpg 760w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware-300x237.jpg 300w\" sizes=\"(max-width: 760px) 100vw, 760px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Restart your phone.<\/p>\n<p>Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.<\/p>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Recover affected accounts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">From a clean device, replace passwords for email, banking, payment, cryptocurrency and social accounts used on the phone. Revoke active sessions, review connected applications and generate new recovery codes.<\/p>\n\n\n\n<div id=\"mwtad1739064037\" class=\"gas_fallback-ad_360584-ad_309691-placement_360775\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3952847241\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">Contact banks or payment providers if credentials, card details or transactions were visible. Ask the mobile carrier to protect the number with an account PIN if SMS messages or verification codes may have been exposed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reset the phone if symptoms remain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A factory reset is appropriate when the app cannot be removed, surveillance symptoms continue or the level of access is uncertain. Back up personal photos and documents carefully, then reinstall trusted apps from official sources instead of restoring the suspicious package.<\/p>\n\n\n\n<div id=\"mwtad2827953445\" class=\"gas_fallback-ad_381392-ad_309691-placement_381395\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How to Protect Android Devices From RATs<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Use official app stores and verify the developer before installing<\/li><li>Never grant Accessibility access merely to activate a downloaded app<\/li><li>Treat APK links in private messages and QR codes as high risk<\/li><li>Keep Android and Google Play system components updated<\/li><li>Review special app access and device administrators regularly<\/li><li>Use unique passwords and strong multi-factor authentication<\/li><li>Remove unknown-app installation permission after legitimate use<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Is Flying Eagle a real Android security tool?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Flying Eagle is a remote access trojan toolkit built to create disguised malicious apps, operate infected phones and steal sensitive information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can I identify it by one app name?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Operators can customize the app&#8217;s name, icon and package information. An unofficial installation combined with excessive permissions is more meaningful than any single filename.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Will uninstalling the app secure my accounts?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Uninstallation stops the installed package, but credentials already captured remain exposed. Passwords, sessions, recovery codes and financial activity must be reviewed separately.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does receiving a link infect the phone?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The typical chain requires the victim to download and install the APK and approve permissions. Delete the message if you did not install anything, and do not forward the link.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Flying Eagle is a confirmed Android RAT toolkit whose changing names and icons are designed to make malicious APK files look trustworthy. Its real functions include screen recording, keylogging, fake login overlays and remote device control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you installed an unofficial app and granted Accessibility access, disconnect the phone immediately. Remove the package, scan the device and secure every important account that was used while the app was present.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Flying Eagle is an Android remote access trojan sold as a customizable toolkit for recording screens, stealing passwords and controlling infected phones.<\/p>\n","protected":false},"author":50,"featured_media":398711,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[2836,2728],"tags":[],"class_list":["post-398719","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-removal-and-popup-scam-alerts","category-trojans","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=398719"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398719\/revisions"}],"predecessor-version":[{"id":398720,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398719\/revisions\/398720"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/398711"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=398719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=398719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=398719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}