Researchers have linked the Flying Eagle Android remote access trojan to fake Chinese police apps, revealing what appears to be a much larger criminal operation. The investigation began with a fraudulent Android app designed to look like an official police-related application, then expanded into a broader review of the infrastructure behind it.

According to the report, Hunt.io researchers worked with independent journalist NetAskari to trace the activity beyond the single fake app. Their findings connected the malware campaign to 170 servers, suggesting that Flying Eagle is part of a growing cybercrime ecosystem rather than an isolated scam.

The case highlights how attackers continue to use trusted government themes to make malicious apps look legitimate. By disguising malware as a Chinese police app, the operators appear to have relied on social engineering as well as technical infrastructure to support the campaign.

The exposed server network also points to an organized backend capable of supporting multiple stages of malicious activity. While the trimmed report does not detail every function of the infrastructure, the researchers’ findings indicate that Flying Eagle has a wider footprint and a more developed support system than a single fake Android app would suggest.