A Chinese-linked spyware platform known as LightSpy has significantly expanded its operations, now targeting victims in more than a dozen countries across Europe, the United States, and other regions.

Security researchers say the malware has evolved beyond its original capabilities and now supports a wide range of devices while introducing new features that can steal sensitive data and even remotely wipe compromised systems.

Researchers at cybersecurity firm Arctic Wolf said LightSpy, first identified in 2018 and previously associated with Chinese state-backed hackers, has transformed into a commercial spyware platform operated by a single threat actor. According to the report, the platform appears to be marketed to governments, military organizations, and enterprises, complete with custom branding, billing systems, and product demonstrations for potential customers.

LightSpy is designed as a modular spyware framework capable of infecting smartphones, Apple devices, Windows computers, Linux servers, and other systems using platform-specific exploits. Once installed, it can collect extensive information from victims, including precise location data, chat messages, stored passwords, and screen recordings. Researchers also found that the spyware includes functionality to remotely erase data, allowing attackers to permanently destroy information on infected devices.

One of the most notable developments is LightSpy’s ability to compromise internet routers, a capability not previously observed by researchers. By targeting routers, attackers can potentially monitor network traffic and gain access to multiple connected devices from a single point of compromise. Arctic Wolf said some of the affected routers are associated with NATO member countries, raising additional security concerns.

READ
UK Police Legal Database Breached, Contact Details of Over 100,000 Officials Exposed

The researchers estimate that the spyware currently operates through at least 117 servers located across several countries, highlighting the scale of its global infrastructure and reach.

Arctic Wolf also uncovered an unusual operational mistake that helped identify one of the spyware operators. According to the report, an administrator reportedly used the LightSpy management panel to place an order with Kentucky Fried Chicken using their real name and office address, allowing researchers to connect the latest activity to a Chinese contractor.


Buy ExpressVPN with PayPal or Credit Card

The findings highlight the continued growth of commercial spyware, which is increasingly being offered beyond nation-state intelligence agencies to government clients, military organizations, and private-sector customers, expanding the global cyber surveillance landscape.

Advertisement