Technology News

China-linked LightSpy spyware expands to 13 countries, adds device-wiping attacks

Security analyst monitoring a world map with red alert markers showing LightSpy spyware infections across multiple countries.

Security researchers have uncovered evidence that the China-linked LightSpy spyware, first identified in 2018, has expanded its reach to target victims in 13 countries, including the United States and several NATO member states. The findings, published Tuesday by cybersecurity firm Arctic Wolf, reveal that the spyware has evolved from a tool used mainly inside mainland China into a commercial platform with new capabilities that can steal vast amounts of data and even remotely brick infected devices.

Arctic Wolf said LightSpy is now operated as a commercial spyware platform by a single threat actor who markets it to governments, enterprises, and militaries. The platform includes custom branding, billing, and demo materials to attract prospective buyers — a sign that spyware is no longer the exclusive domain of nation-state hackers.

Also read: Cloudflare launches Kitesurf, a cloud-hosted browser built for AI agents

From targeted attacks to a commercial product

LightSpy was originally discovered in 2018 and was previously attributed to Chinese state-backed hacking groups. But Arctic Wolf’s analysis shows it has since morphed into a modular platform that can attack a wide range of devices: smartphones, Apple devices, Linux servers, Windows PCs, and — for the first time — routers.

The new router attacks are particularly concerning, according to the researchers. By compromising a router, the operators gain visibility into and access to every other device on the same network. Some of the compromised routers were found in NATO member countries, Arctic Wolf said, though it did not specify which ones.

Also read: Rippling's AI bill hit 40% of its R&D budget. Now it's selling the fix.

The spyware’s data-stealing capabilities are extensive. It can capture precise location data, chat messages, screen recordings, and stored passwords. The code also includes a module capable of remotely wiping and destroying data on a compromised device, effectively bricking it.

Arctic Wolf said LightSpy operates a network of at least 117 servers spread across several countries. The researchers were able to tie the latest activity to a Chinese contractor after one of the spyware’s operators used the LightSpy administrator’s panel to place an order with Kentucky Fried Chicken using his real name and office address.

What this means for the spyware industry

The findings underscore how the commercial spyware market has expanded beyond traditional government buyers. In recent years, firms like NSO Group and Cytrox have faced scrutiny for selling surveillance tools to authoritarian regimes, but LightSpy’s evolution shows that state-linked hacking groups are also adapting to a business model.

“This is no longer just about governments spying on dissidents,” said John Scott-Railton, a senior researcher at Citizen Lab who has tracked spyware for years. “We’re seeing a convergence where state-developed tools are being commercialized and sold to a broader clientele, including private industry.”

The expansion of LightSpy also raises concerns about the security of critical infrastructure. With the ability to target routers and servers, the spyware could be used to gain a foothold in corporate networks, potentially leading to data breaches or ransomware attacks.

For individual users, the threat is less direct but still relevant. The spyware’s ability to steal passwords and screen recordings means that anyone with a vulnerable device could be at risk, especially if they are a person of interest to a government or a competitor.

Arctic Wolf has not yet published a full technical report, but the company said it is working with affected organizations and law enforcement. The researchers urged network administrators to patch router firmware and monitor for unusual traffic patterns.

This is a developing story. More details are expected as Arctic Wolf releases its full findings. In the meantime, the takeaway for security teams is clear: the threat sector is no longer limited to traditional malware — commercial spyware is now a mainstream risk.

This article is for informational purposes only and does not constitute financial or investment advice. The cybersecurity market is volatile and subject to rapid change; readers should conduct their own research before making any decisions.

Neelima Kumar

Written by

Neelima Kumar

Neelima Kumar covers technology and artificial intelligence for StockPil, tracking how emerging tech trends intersect with markets and business.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

To Top