Security researchers have uncovered evidence that the LightSpy spyware, initially discovered in 2018 and previously associated with Chinese state-backed hacking groups, has transformed into a commercial spyware platform. This evolved platform is now targeting victims in over a dozen countries, spanning Europe and the United States, as well as NATO member countries.
The commercialized LightSpy platform offers custom branding, billing, and demonstrations to prospective clients, including governments, enterprises, and militaries. This shift signifies a broader proliferation of spyware beyond state actors into the private sector.
LightSpy is a modular system designed to attack various devices, including smartphones, Apple devices, Linux servers, and Windows PCs. It leverages device-specific exploits to steal a wide range of sensitive information, such as precise location data, chat messages, screen recordings, and stored passwords. Additionally, the spyware possesses the capability to remotely wipe and destroy data on compromised devices.
A new development noted by researchers is LightSpy's ability to infect routers. By compromising routers, attackers can gain visibility and access to all other devices connected to the same network. The researchers linked the latest activity to a Chinese contractor after an operator inadvertently revealed their identity by using their real name and office address when placing a food order through the LightSpy administrator's panel.