← Back to the feed

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

TechCrunch ·

Security researchers at Arctic Wolf have found that LightSpy, a spyware platform previously linked to Chinese state-backed hackers, has expanded well beyond mainland China to target victims in 13 countries, including the US and several across Europe. It has also gained new capabilities, allowing it to steal large volumes of data and remotely wipe compromised devices, and researchers say it now operates as a commercial spyware-for-hire platform with custom branding and billing, marketed to governments, enterprises and militaries.

LightSpy, first identified in 2018, is a modular tool able to compromise smartphones, Apple devices, Linux servers and Windows PCs, harvesting location data, chat messages, screen recordings and stored passwords. Researchers said it has also been found infecting routers for the first time, including some linked to NATO member states, giving attackers visibility into every device on a compromised network. Arctic Wolf identified a network of at least 117 servers worldwide and traced the latest activity to a Chinese contractor after an operator reportedly used the spyware's admin panel to place a food delivery order under his real name and office address.

  • LightSpy spyware now targets victims in 13 countries, including the US
  • It can steal vast data troves and remotely wipe devices
  • Operator's own food order slip-up helped researchers trace it to China

Americas Asia Business Companies Research Science World

Read the full article at the source →