Security researchers at Arctic Wolf have reported that the LightSpy spyware, initially discovered in 2018, has broadened its operational scope beyond mainland China. The spyware is now targeting individuals and entities in over a dozen countries, including the United States and various European nations. This expansion indicates a significant increase in the reach of the threat actor behind LightSpy.
LightSpy has evolved into a commercial spyware platform, operated by a single threat actor who offers its services to governments, enterprises, and militaries. The platform includes custom branding, billing, and demonstration features for prospective clients. Its new functionalities allow for extensive data exfiltration, including precise location data, chat messages, screen recordings, and stored passwords. The spyware can also remotely wipe and destroy data on compromised devices.
A notable development in LightSpy's deployment is its ability to infect routers, a method not previously observed by researchers. By compromising routers, the attackers gain visibility and access to all other devices connected to the same network. Arctic Wolf noted that some of the compromised routers are associated with NATO member countries, highlighting a potential national security concern.
Researchers were able to link the recent LightSpy activity to a Chinese contractor after one of the spyware's operators used the administrator's panel to place a Kentucky Fried Chicken order with their real name and office address. The spyware operates a network of at least 117 servers located in various countries globally, supporting its widespread operations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The China-linked LightSpy spyware, previously identified in 2018, has expanded its targeting to include victims in 13 countries, including the US and European nations. This modular spyware platform now features new capabilities for data exfiltration and remote device wiping, and has been observed infecting routers, including some in NATO member countries.