LightSpy spyware hits 13 countries, including US, and can now brick devices

Security researchers at Arctic Wolf have found that LightSpy, a spyware previously linked to Chinese state-backed hackers, has evolved into a commercial platform that now targets victims in more than a dozen countries, including Europe and the United States. First identified in 2018, the tool has gained new capabilities that allow it not only to steal vast amounts of data but also to remotely disable infected devices.
According to the company, LightSpy is operated by a single actor who offers services to governments, corporations, and militaries. The platform includes custom branding, a billing system, and demo materials to attract prospective customers. This highlights how spyware use is spreading beyond state structures and increasingly into the private sector.
LightSpy is a modular system capable of attacking a wide range of devices: smartphones, Apple products, Linux servers, and Windows PCs. Using exploits tailored to each device type, the program extracts sensitive information from targets, including precise location data, chat messages, screen recordings, and saved passwords. The code can also completely wipe and destroy data on a compromised device.
The researchers separately noted a new tactic: LightSpy now infects routers, something not seen before. Compromising network equipment gives hackers access to any other device on the same network. Some of the affected routers are said to be linked to NATO member states.
LightSpy's infrastructure includes at least 117 servers spread across several countries. The researchers managed to link recent activity to a Chinese contractor after one of the platform's operators, using the LightSpy admin panel, placed an order at Kentucky Fried Chicken with his real name and office address.


