Cybersecurity researchers at Arctic Wolf have reported that the LightSpy spyware campaign has expanded far beyond China, now targeting victims in more than 13 countries, including the United States and several European nations. First identified in 2018 and previously linked to Chinese state-backed hackers, LightSpy has evolved into a commercial surveillance platform operated by a single threat actor that provides services to governments, businesses, and military organizations.
LightSpy is a modular spyware platform capable of compromising a wide range of devices, including smartphones, Apple devices, Linux servers, and Windows computers. By exploiting software vulnerabilities, it can steal large amounts of sensitive information, including precise location data, messages, screen recordings, and stored passwords.
The malware also has the capability to remotely erase and destroy data from infected devices.
According to Arctic Wolf, LightSpy has recently been observed infecting internet routers—a capability researchers say they had not previously documented. By compromising routers, attackers can gain visibility into and potentially access every device connected to the same network.
Some of the compromised routers are located in NATO member states, raising additional security concerns.
The company estimates that LightSpy operates through a network of at least 117 servers distributed across multiple countries. The platform also includes commercial-style features such as custom branding, billing systems, and product demonstrations designed to attract potential clients.
Researchers were able to link the latest activity to a Chinese contractor after one of the spyware operators reportedly used the malware’s administrative panel to place an order through the Kentucky Fried Chicken (KFC) network, using his real name and office address.
