← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

LightSpy Spyware Expands Global Reach, Targets 13 Countries Including US

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • LightSpy spyware now targets 13 countries, including the US and Europe.
  • New functionality includes data theft, screen recording, and remote device wiping.
  • The spyware has been found infecting routers, including those in NATO countries.
  • Researchers linked activity to a Chinese contractor via an ordering error.

LightSpy's Expanded Global Operations

Security researchers at Arctic Wolf have reported that the LightSpy spyware, initially discovered in 2018, has broadened its operational scope beyond mainland China. The spyware is now targeting individuals and entities in over a dozen countries, including the United States and various European nations. This expansion indicates a significant increase in the reach of the threat actor behind LightSpy.

New Capabilities and Commercialization

LightSpy has evolved into a commercial spyware platform, operated by a single threat actor who offers its services to governments, enterprises, and militaries. The platform includes custom branding, billing, and demonstration features for prospective clients. Its new functionalities allow for extensive data exfiltration, including precise location data, chat messages, screen recordings, and stored passwords. The spyware can also remotely wipe and destroy data on compromised devices.

Router Infections and Network Access

A notable development in LightSpy's deployment is its ability to infect routers, a method not previously observed by researchers. By compromising routers, the attackers gain visibility and access to all other devices connected to the same network. Arctic Wolf noted that some of the compromised routers are associated with NATO member countries, highlighting a potential national security concern.

Attribution and Infrastructure

Researchers were able to link the recent LightSpy activity to a Chinese contractor after one of the spyware's operators used the administrator's panel to place a Kentucky Fried Chicken order with their real name and office address. The spyware operates a network of at least 117 servers located in various countries globally, supporting its widespread operations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The China-linked LightSpy spyware, previously identified in 2018, has expanded its targeting to include victims in 13 countries, including the US and European nations. This modular spyware platform now features new capabilities for data exfiltration and remote device wiping, and has been observed infecting routers, including some in NATO member countries.