Cybersecurity

LightSpy spyware targets victims in 13 countries, including US

1 min read

LightSpy spyware targets victims in 13 countries, including US
Photo: Markus Spiske · Unsplash
0 0
XWhatsAppTelegramLinkedIn

China-linked spyware LightSpy has spread to victims in 13 countries, including the United States, and can now infect routers, security firm Arctic Wolf said on August 6, 2026.

First discovered in 2018 and long tied to Chinese state-backed hackers, the spyware has evolved into a commercial platform run by a single threat actor, the researchers reported.

The platform offers custom branding, billing and demonstrations to pitch to governments, enterprises and militaries.

Once inside a router, the attacker can see and reach any device on the same network. Some compromised routers are linked to NATO member countries, Arctic Wolf added.

LightSpy is a modular malware that can invade smartphones, Apple devices, Linux servers and Windows PCs. It steals precise location data, chat messages, screen recordings and stored passwords, and can remotely wipe or destroy data on compromised machines.

The espionage campaign runs on at least 117 servers in multiple countries, the firm said.

Investigators tied the latest activity to a Chinese contractor after one operator used the spyware’s admin panel to order Kentucky Fried Chicken, entering his real name and office address.

The commercialization of LightSpy underscores how spyware is moving beyond governments into the private sector, the report concluded.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.