LightSpy is a modular, Chinese-linked commercial spyware platform first publicly identified in 2018. It has targeted mobile devices and Apple systems, with reported later variants and operations affecting Android, Windows, Linux, and network devices. An iOS LightSpy operation, tracked as Operation Poisoned News, targeted Hong Kong users through compromised or cloned news-themed watering-hole pages and exploited vulnerable Safari/WebKit and kernel components to install the implant with elevated privileges. Later iOS activity used additional publicly known WebKit and privilege-escalation vulnerabilities.
The spyware supports extensive surveillance and post-compromise control through downloadable modules. Documented iOS capabilities include remote shell-command execution; file browsing and manipulation; collection of device metadata, contacts, SMS and call history, running processes, installed applications, location data, Wi-Fi history and nearby-network information, browser history, and messaging-application data. It can extract Keychain items, including passwords, certificates, and keys, and exfiltrate data through encrypted web traffic and WebSockets. Newer iOS variants added audio and camera collection, simulated notifications, and destructive modules capable of freezing a device or interfering with booting. LightSpy has also been reported to collect chat content, stored passwords, and screen recordings, and to remotely delete data.
LightSpy infrastructure and implants exhibit code overlap across Apple platforms, indicating common development. Public reporting has assessed the operation as controlled by a single China-linked actor and potentially offered as a commercial surveillance service to government, military, and enterprise customers; the identities of customers and the precise relationship to the Chinese government remain unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The full exploit chain involves exploiting a silently patched Safari bug on multiple recent iOS versions and a customized kernel exploit. Once the Safari browser renders the exploit, a silently patched bug is taken advantage of, which leads to the exploitation of a known kernel vulnerability to gain root privileges. The exploited kernel bug has been assigned with the CVE ID CVE-2019-8605. | The iOS malware, which we named "lightSpy" (detected by Trend Micro as IOS_LightSpy.A), is a modular backdoor that allowed the attacker to remotely execute a shell command and manipulate files on the infected device.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access... This time it was CVE-2020-9802, which was fixed in iOS 13.5 | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access and CVE-2020-3837 for privilege escalation... The threat actor created "20012001330.png" to trigger vulnerability CVE-2020-3837 using a “time_waste” exploit and a corresponding jailbreak kit. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2020, a watering hole was discovered that utilized a full remote iOS exploit chain to deploy a feature-rich implant named LightSpy.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Users with unpatched iPhones that access the concerned links will be infected with an iOS malware that can spy on and take full control of the devices. | Trend Micro discovered a watering hole attack against iOS users in Hong Kong... The campaign designed several webpages disguised as local news pages then injected them with an iframe that loads an iOS exploit.
After downloading all the payloads, the exploit spawns a daemon using launchctl with “ircbin.plist” as the argument.
The iOS malware, which we named "lightSpy"... allowed the attacker to remotely execute a shell command...
This daemon uses irc_loader as an executable. This loader is just a launcher and will be used to start up the main malicious agent deployed on the target side.
After downloading all the payloads, the exploit spawns a daemon using launchctl with “ircbin.plist” as the argument.
Once the Safari browser renders the exploit, a silently patched bug is taken advantage of, which leads to the exploitation of a known kernel vulnerability to gain root privileges. The exploited kernel bug has been assigned with the CVE ID CVE-2019-8605.
The startup parameters are hidden in the irc_loader binary and are encrypted with the AES algorithm.
The campaign also employs modules specifically designed to exfiltrate data from popular messenger applications such as QQ, WeChat, and Telegram.
The malware also reports the surrounding environment of the device by: Scanning local network IP address; Scanning available Wi-Fi network.
Command 16002 is used to get the process list... it first calls the “ps -Aef” command to get the process list...
This module is mainly for gathering and uploading information such as iPhone hardware information...
This module is mainly used for file or directory operation, including the following sub-commands: get directory and file list... and get the directories of applications.
It is mainly used to get the device’s browser history for Safari and Chrome.
After that, it initializes a thread using the libwebsockets library to implement the messages' receiving function.
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular commercial spyware platform reportedly linked to Chinese state-backed activity and operated by a single actor for multiple customers. It targets smartphones, Apple devices, Windows computers, Linux servers, and newer versions target internet routers. It collects location data, chats, passwords, and screen recordings, and can remotely delete files or render compromised devices unusable.
A modular commercial spyware platform linked to Chinese state-backed activity that infects smartphones, Apple devices, Linux servers, Windows PCs, and routers via device-specific exploits. It steals sensitive data including location, chat messages, screen recordings, and passwords, can remotely wipe devices, and router infections provide visibility and access across compromised networks.
A modular spyware platform capable of targeting smartphones, Apple devices, Linux servers, Windows PCs, and routers. It uses device-specific exploits to steal sensitive data such as location data, chat messages, screen recordings, and stored passwords, and can also remotely wipe or destroy data on compromised devices.
Modular spyware implant with expanded command set; targets multiple OSes and harvests data including from social media platforms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.