China-linked LightSpy spyware targets victims in 13 countries
window 24h
IN SHORT
A sophisticated spyware known as LightSpy, previously associated with Chinese state-backed actors, has transitioned into a commercial operation, targeting individuals and organizations across 13 countries, including the United States and NATO members. This advanced malware is capable of exfiltrating sensitive data and remotely wiping devices. In a separate development, Chinese router manufacturer Zbtlink Electronics is halting sales of certain router models and removing compromised software due to a discovered backdoor vulnerability that could permit unauthorized network access and control.
✉Newsletter
PiQ Daily
Pick your topics. Get only what matters, on your cadence.
Who's Involved
LightSpy
spyware linked to Chinese state-backed hackers now operating as a commercial platform
China
country linked to state-backed hackers and router manufacturer Zbtlink
US
country targeted by LightSpy spyware
NATO members
countries targeted by LightSpy spyware
Zbtlink Electronics
Chinese router maker suspending sales over vulnerability
cybersecurity firm
entity that discovered the backdoor vulnerability in Zbtlink routers
Key facts
LightSpy spyware is linked to Chinese state-backed hackers.
LightSpy spyware has transitioned into a commercial platform.
LightSpy spyware targets victims in 13 countries.
The US and NATO members are among the countries targeted by LightSpy.
LightSpy spyware can steal sensitive data.
LightSpy spyware can remotely destroy devices.
Zbtlink Electronics is a Chinese router manufacturer.
Zbtlink is suspending sales of affected router models.
Zbtlink is removing compromised software.
A backdoor vulnerability was discovered in Zbtlink routers.
The vulnerability could allow unauthorized access and control of devices.
The LightSpy spyware, which has prior links to Chinese state-backed hacking groups, has reportedly evolved into a commercial platform. Security researchers have identified this spyware actively targeting victims in more than 13 countries worldwide. Among the affected nations are the United States and several NATO member states, indicating a broad scope of operation. The advanced capabilities of LightSpy include the ability to steal sensitive user data and the potential to remotely destroy targeted devices. This shift from state-sponsored activity to a commercial model suggests a new phase in its deployment and accessibility.
In parallel, Zbtlink Electronics, a Chinese company specializing in router manufacturing, has announced a suspension of sales for specific router models. This action follows the discovery of a significant backdoor vulnerability within the devices' software. A cybersecurity firm identified the flaw, which could potentially allow unauthorized individuals to gain access to and exert control over devices connected to the affected networks. Zbtlink is also in the process of removing the compromised software from its systems in response to this security lapse.
The implications of these developments are significant for cybersecurity. The commercialization of advanced spyware like LightSpy lowers the barrier for malicious actors to acquire and deploy sophisticated surveillance and destructive tools. The vulnerability found in Zbtlink routers highlights ongoing concerns about supply chain security and the potential for widespread compromise of internet-connected devices, which form the backbone of modern digital infrastructure.
↳ Why This Matters
The LightSpy spyware, which has prior links to Chinese state-backed hacking groups, has reportedly evolved into a commercial platform. Security researchers have identified this spyware actively targeting victims in more than 13 countries worldwide. Among the affected nations are the United States and several NATO member states, indicating a broad scope of operation. The advanced capabilities of LightSpy include the ability to steal sensitive user data and the potential to remotely destroy targeted devices. This shift from state-sponsored activity to a commercial model suggests a new phase in its deployment and accessibility.
Frequently asked questions
LightSpy is a modular spyware platform, first discovered in 2018, that has evolved into a commercial product. It is capable of stealing sensitive data from various devices and remotely destroying data.
Researchers link the spyware to a Chinese contractor, and it was previously associated with Chinese state-backed hackers. It now operates as a commercial platform sold to governments, enterprises, and militaries.
The spyware can now infect routers, gaining access to all devices on the same network. It also has enhanced capabilities for stealing sensitive data and remotely wiping devices.
Victims have been identified in over a dozen countries, including the United States and several NATO member countries.
What Happens Next
01Further investigation into the commercial operations of LightSpy.
02Monitoring for additional targets and countries affected by the spyware.
Get the newsletter.
Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.