LightSpy is a modular spyware platform first identified in 2018 and associated with Chinese-linked surveillance activity. It has been described as evolving from a targeted mobile espionage implant into a broader commercial spyware offering operated by a single threat actor and marketed to government, enterprise, and military customers. Activity attributed to LightSpy has expanded from an earlier focus on mainland China to victims in multiple countries across Europe and the United States.
LightSpy is best known for targeting Apple ecosystems, including iOS and macOS, but reporting also indicates variants or campaigns affecting Android, Windows, Linux, and routers through device-specific exploitation. On iOS, LightSpy has been delivered through watering-hole operations using cloned news sites and malicious web pages that served Safari/WebKit exploit chains followed by privilege escalation. More recent reporting indicates shared infrastructure between macOS and iOS campaigns and substantial code overlap across those implants.
The malware functions as a modular backdoor and spyware framework. It can remotely execute commands, profile infected devices, collect phone and hardware metadata, access contact lists, call logs, SMS messages, browser history, and files from messaging applications including Telegram, QQ, WeChat, and WhatsApp. Reported plugins and modules also support location tracking, Wi-Fi and nearby network reconnaissance, theft of stored passwords and Keychain data, screen recording, audio or camera collection, and exfiltration of harvested data to command-and-control infrastructure using HTTPS and WebSockets. Some variants can send and delete SMS messages, simulate push notifications, and scan local or adjacent networks.
LightSpy also includes destructive functionality in some observed versions. Reported modules can remotely wipe or destroy data, freeze devices, or interfere with the boot process, indicating that the platform supports both surveillance and disruptive effects. Router compromises attributed to LightSpy are notable because they can provide operators visibility into and access to other devices on the affected network.
Observed targeting has included residents of Hong Kong in earlier iPhone watering-hole campaigns, as well as broader international victims in later operations. Researchers have linked LightSpy to Chinese state-backed activity in earlier reporting and later assessed it as a likely China-based commercial spyware operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access... This time it was CVE-2020-9802, which was fixed in iOS 13.5 | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access and CVE-2020-3837 for privilege escalation... The threat actor created "20012001330.png" to trigger vulnerability CVE-2020-3837 using a “time_waste” exploit and a corresponding jailbreak kit. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The technical details around the functionality of the iOS implant, called LightSpy… reveal a low-to-mid capable actor. However, the iOS implant is a modular and exhaustively functional iOS surveillance framework.”
32 distinct techniques documented for this family, organized by ATT&CK tactic.
experts detected a large-scale watering-hole attack aimed at residents of Hong Kong... The malware landed on victims’ smartphones when they visited one of several websites disguised as local news resources | All it took for the iPhone to get infected was one visit to a malicious page. There was no need even to tap anything.
Bootdestroy plugin... will spawn the shell and execute the following shell command: /usr/sbin/nvram auto-boot=false .
FrameworkLoader will call two functions: _inject and trustBin... copied from the 'jelbrek.m' file... This file will try to inject libcynject.dylib into SpringBoard process.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
AppDelete... Can delete messenger-related victim files... BrowserDelete... can wipe browser history... ContactDelete... can delete specified contacts... MediaDelete... deleting media files... SMSDelete... deletes specified SMS message
Royal can scan the network interfaces of targeted systems. LightSpy reads the host's Wi‑Fi connection history and utilizes Apple's CWWiFiClient API to scan for nearby Wi‑Fi networks and obtain SSID, security type, and RSSI values.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2. | Examples include 'Drovorub ... initiated communication with C2 servers with an HTTP Upgrade request' and 'COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control.'
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
122 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular commercial spyware platform linked to Chinese state-backed activity that infects smartphones, Apple devices, Linux servers, Windows PCs, and routers via device-specific exploits. It steals sensitive data including location, chat messages, screen recordings, and passwords, can remotely wipe devices, and router infections provide visibility and access across compromised networks.
A modular spyware platform capable of targeting smartphones, Apple devices, Linux servers, Windows PCs, and routers. It uses device-specific exploits to steal sensitive data such as location data, chat messages, screen recordings, and stored passwords, and can also remotely wipe or destroy data on compromised devices.
Modular spyware implant with expanded command set; targets multiple OSes and harvests data including from social media platforms.
Cross-platform surveillance framework affecting macOS and other OSes, enabling surveillance and data exfiltration; described as often linked to Chinese APT groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.