LightSpy spyware activity identified across 13 countries

Arctic Wolf has identified activity linked to the LightSpy spyware platform in 13 countries, including the United States and countries across Europe. The cybersecurity firm said the infrastructure behind the operation includes at least 117 servers in several countries, while some compromised routers were associated with NATO member countries.
LightSpy was first discovered in 2018 and had previously been linked to Chinese state-backed hackers. Arctic Wolf now describes it as a commercial spyware platform operated by a single threat actor serving governments, enterprises and militaries. The researchers said the platform includes custom branding, billing and demonstrations intended for prospective customers.
A modular platform with destructive capabilities
LightSpy is designed to target multiple device categories. Arctic Wolf said it can be used against smartphones, Apple devices, Linux servers and Windows PCs, using exploits tailored to the device being attacked.
Once a device is compromised, the platform can collect precise location data, chat messages, screen recordings and stored passwords. Its code can also remotely wipe and destroy data on an affected device, adding a destructive capability to its surveillance functions.
The latest findings also include LightSpy infections on routers, a deployment route Arctic Wolf said it had not observed before. A compromised router can provide an operator with visibility and access to other devices connected to the same network.
Infrastructure and attribution clues
Arctic Wolf said it linked the latest activity to a Chinese contractor after an operator used the LightSpy administrator panel to order Kentucky Fried Chicken with a real name and office address. The finding adds an operational detail to the researchers’ assessment of the actor behind the current activity.
The researchers’ description points to spyware use extending beyond government and state-backed operations into private industry. LightSpy’s reported customer-facing functions, broad device coverage and router targeting make it relevant to organisations operating mixed endpoint and network environments.
Business implication
Businesses should treat routers as monitored security assets rather than passive network equipment, maintain patching, review administrative activity and investigate unusual access that could expose connected devices and sensitive information.

