Arctic Wolf researchers reported that LightSpy, a spyware family first identified in 2018, has expanded from targeting mainland China to victims in 13 countries, including the United States and parts of Europe. The malware has evolved into a modular commercial spyware platform that can infect smartphones, Apple devices, Linux servers, Windows PCs, and routers, reportedly serving governments, enterprises, and militaries through custom branding and billing.
Researchers said LightSpy can steal location data, chat messages, screen recordings, and passwords, while also giving operators the ability to remotely wipe or destroy data on compromised devices. Its expansion to routers is especially significant because it can provide visibility into all devices on affected networks; some compromised routers were linked to NATO member countries. Arctic Wolf identified at least 117 servers supporting the operation worldwide and said an operational security mistake in the administration panel exposed the activity's link to a Chinese contractor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
LightSpy was first discovered in 2018 as a spyware family that had previously focused on targets in mainland China.
Researchers linked recent LightSpy activity to a Chinese contractor after an operator exposed his real name and office address through the spyware administration panel while placing a personal KFC order. The operational security mistake provided attribution evidence for the latest activity.
Arctic Wolf assessed that LightSpy evolved from a previously identified spyware strain into a modular commercial spyware platform run by a single threat actor. The operator was said to market the tool to governments, enterprises, and militaries with custom branding, billing, and demos.
Arctic Wolf reported that LightSpy had expanded beyond mainland China to target victims in more than a dozen countries, including Europe and the United States. The researchers also observed infections on routers, including some associated with NATO member countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.