China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Security researchers at Arctic Wolf have found evidence that the China-linked LightSpy spyware has expanded beyond mainland China to target victims in more than a dozen countries, including the US and Europe, with capabilities for mass data theft and remote device destruction.

Security researchers say they have evidence that a Chinese-linked spyware has expanded its reach from mainland China to victims in more than a dozen countries, including across Europe and the United States. The previously identified spyware also gained new functionality capable of stealing large amounts of data and remotely bricking devices.
The researchers at cybersecurity firm Arctic Wolf said that LightSpy, first discovered in 2018 and previously linked to Chinese state-backed hackers, has since evolved into a commercial spyware platform operated by a single threat actor who caters to governments, enterprises, and militaries. The platform features custom branding, billing, and demos for advertising to prospective customers.
LightSpy is a modular spyware platform that enables its controller to attack a variety of devices, including smartphones, Apple devices, Linux servers, and Windows PCs. By exploiting vulnerabilities in each device, the spyware can steal sensitive information such as precise location data, chat messages, screen recordings, and stored passwords. The researchers also said the code is capable of remotely wiping and destroying data on a compromised device.
For the first time, the researchers observed LightSpy infecting routers, which allows the attackers to gain visibility and access to any other device on the same network. Some of the compromised routers are associated with NATO member countries, according to Arctic Wolf.
The company said LightSpy operates a network of at least 117 servers across several countries. The researchers linked the latest activity to a Chinese contractor after one of the spyware’s operators used the LightSpy administrator’s panel to place an order with Kentucky Fried Chicken using his real name and office address.


