Researchers at cybersecurity firm Arctic Wolf found that China-linked LightSpy spyware, first discovered in 2018, has expanded from mainland China to target victims in over a dozen countries, including across Europe and the US. The modular platform now includes functionality to steal large troves of data, infect routers, and remotely wipe or brick compromised devices, and has evolved into a commercial spyware platform marketed to governments, enterprises and militaries.
LightSpy was previously linked to Chinese state-backed hackers but has since been repackaged as a commercial surveillance product operated by a single threat actor with custom branding, billing and demonstrations. It attacks smartphones, Apple devices, Linux servers and Windows PCs, using device-specific exploits to steal location data, chat messages, screen recordings and stored passwords.
The expansion demonstrates how sophisticated state-origin spyware is proliferating into a commercial market, broadening its reach beyond nation-state targets to the private sector. The new ability to remotely brick devices and infect routers raises the stakes significantly for individuals and organisations that find themselves compromised.

Researchers at cybersecurity firm Arctic Wolf found that China-linked LightSpy spyware, first discovered in 2018, has expanded from mainland China to target victims in over a dozen countries, including across Europe and the US. The modular platform now includes functionality to steal large troves of data, infect routers, and remotely wipe or brick compromised devices, and has evolved into a commercial spyware platform marketed to governments, enterprises and militaries.

LightSpy was previously linked to Chinese state-backed hackers but has since been repackaged as a commercial surveillance product operated by a single threat actor with custom branding, billing and demonstrations. It attacks smartphones, Apple devices, Linux servers and Windows PCs, using device-specific exploits to steal location data, chat messages, screen recordings and stored passwords.

The expansion demonstrates how sophisticated state-origin spyware is proliferating into a commercial market, broadening its reach beyond nation-state targets to the private sector. The new ability to remotely brick devices and infect routers raises the stakes significantly for individuals and organisations that find themselves compromised.

πŸ“° Source: TechCrunch
techcrunch.com β†—
Was this article useful?