LightSpy Spyware Expands to 13 Countries Including the US

Original: China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

Why This Matters

LightSpy's commercial expansion signals growing proliferation of state-grade spyware into private markets globally.

Arctic Wolf researchers report that the China-linked LightSpy spyware has expanded from mainland China to over 13 countries, including the US and Europe. The modular platform now targets routers, including those in NATO member countries, and operates across at least 117 servers worldwide.

Cybersecurity firm Arctic Wolf has published findings showing that LightSpy, a modular spyware first discovered in 2018 and previously attributed to Chinese state-backed hackers, has evolved into a commercial spyware platform targeting victims in more than 13 countries, including the United States and multiple European nations. The platform is marketed to governments, enterprises, and militaries with custom branding, billing systems, and demos. LightSpy is capable of attacking smartphones, Apple devices, Linux servers, and Windows PCs. It can steal location data, chat messages, screen recordings, and stored passwords, and can remotely wipe or brick compromised devices. Researchers newly identified LightSpy infections on routers, a capability not previously observed, enabling attackers to monitor and access all devices on the same network. Some compromised routers are linked to NATO member countries. The spyware infrastructure includes at least 117 servers globally. Researchers were able to attribute recent activity to a Chinese contractor after one operator inadvertently used the LightSpy admin panel to place a KFC order under his real name and office address.

Source

techcrunch.com — Read original →