All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

China-linked LightSpy spyware targets victims in 13 countries

Created at 6 Aug · 7:51 PM1 source↑ Market-relevant
IN SHORT

Security researchers have identified the LightSpy spyware, previously linked to Chinese state-backed hackers, now operating as a commercial platform targeting victims in over a dozen countries, including the US and NATO members. The evolved spyware can steal sensitive data and remotely destroy devices.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

13countries targeted by LightSpy spyware
2018year LightSpy spyware was first discovered
117servers operated by LightSpy network

Who's Involved

Arctic Wolf
cybersecurity firm that identified LightSpy's evolution
LightSpy
China-linked commercial spyware platform
China-linked LightSpy spyware targets victims in 13 countries

↳ Why This Matters

The evolution of LightSpy into a commercial product highlights the increasing accessibility and proliferation of sophisticated spyware beyond government use, posing a broader threat to individuals, businesses, and national security, including within NATO countries.

Key facts

  • LightSpy spyware, previously linked to Chinese state-backed hackers, has expanded its targets.
  • The spyware now operates as a commercial platform catering to governments, enterprises, and militaries.
  • Victims have been identified in over a dozen countries, including the US and NATO member states.
  • The spyware can steal sensitive data such as chat messages, location data, and passwords.
  • LightSpy is capable of remotely wiping and destroying data on compromised devices.
  • The spyware has been observed infecting routers, granting access to other devices on the same network.

Security researchers have uncovered evidence that the LightSpy spyware, initially discovered in 2018 and previously associated with Chinese state-backed hacking groups, has transformed into a commercial spyware platform. This evolved platform is now targeting victims in over a dozen countries, spanning Europe and the United States, as well as NATO member countries.

The commercialized LightSpy platform offers custom branding, billing, and demonstrations to prospective clients, including governments, enterprises, and militaries. This shift signifies a broader proliferation of spyware beyond state actors into the private sector.

LightSpy is a modular system designed to attack various devices, including smartphones, Apple devices, Linux servers, and Windows PCs. It leverages device-specific exploits to steal a wide range of sensitive information, such as precise location data, chat messages, screen recordings, and stored passwords. Additionally, the spyware possesses the capability to remotely wipe and destroy data on compromised devices.

A new development noted by researchers is LightSpy's ability to infect routers. By compromising routers, attackers can gain visibility and access to all other devices connected to the same network. The researchers linked the latest activity to a Chinese contractor after an operator inadvertently revealed their identity by using their real name and office address when placing a food order through the LightSpy administrator's panel.

Frequently asked questions

LightSpy is a modular spyware platform, first discovered in 2018, that has evolved into a commercial product. It is capable of stealing sensitive data from various devices and remotely destroying data.

Researchers link the spyware to a Chinese contractor, and it was previously associated with Chinese state-backed hackers. It now operates as a commercial platform sold to governments, enterprises, and militaries.

The spyware can now infect routers, gaining access to all devices on the same network. It also has enhanced capabilities for stealing sensitive data and remotely wiping devices.

Victims have been identified in over a dozen countries, including the United States and several NATO member countries.

What Happens Next

01Further investigation into the commercial operations of LightSpy.
02Monitoring for additional targets and countries affected by the spyware.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

LightSpy spyware, first discovered in 2018, has evolved into a commercial platform.
The spyware now targets victims in over a dozen countries, including the US and NATO members.
New functionality allows the spyware to steal sensitive data and remotely destroy devices.
LightSpy has been identified infecting routers, providing access to other devices on the same network.
Researchers linked the activity to a Chinese contractor after an operator used a real name and address.

Sources

T1
China-linked LightSpy spyware caught targeting victims in 13 countries, including the USTechCrunch

Related Stories

China's Zbtlink suspends router sales over backdoor vulnerability
6 Aug · 6:23 PM
Chinese satellite captures video of SpaceX rocket debris crashing into the moon
6 Aug · 12:06 PM
Thousands of servers vulnerable to backdoor exploits via motherboard controllers
5 Aug · 10:51 PM
Meta AI model breached third-party system during testing
6 Aug · 2:11 AM
Google: Hackers use phone calls to extort financial firms
6 Aug · 7:51 PM