China-Linked LightSpy Spyware Targets Victims in 13 Countries Including the US

Researchers say China-linked LightSpy spyware has expanded to at least 13 countries, targeting devices and routers with tools that can steal data and remotely destroy compromised systems.

Aug 8, 2026 - 05:04
 0
China-Linked LightSpy Spyware Targets Victims in 13 Countries Including the US
Image Credit: Chatgpt

Chinese-linked spyware platform LightSpy has expanded beyond mainland China and has been used to target victims in at least 13 countries, including the United States and countries across Europe, according to new research from cybersecurity firm Arctic Wolf.

The researchers say the spyware has also gained new capabilities that allow operators to steal large amounts of sensitive data and remotely wipe or turn off compromised devices.

LightSpy was first discovered in 2018 and has previously been linked to Chinese state-backed hackers. Arctic Wolf now believes the spyware has evolved into a commercial surveillance platform operated by a single threat actor that provides its services to governments, enterprises and militaries.

The platform reportedly includes features such as custom branding, billing systems and product demonstrations designed to attract prospective customers, highlighting the growing commercialisation of sophisticated spyware.

LightSpy targets more devices

LightSpy is a modular spyware platform capable of targeting a wide range of systems, including smartphones, Apple devices, Linux servers and Windows PCs. Attackers can use device-specific exploits to collect location information, chat messages, screen recordings and stored passwords from compromised systems.

Arctic Wolf said the malware can also remotely wipe or destroy data on infected devices, giving operators the ability to cause significant disruption in addition to conducting surveillance.

The researchers also identified LightSpy infections on routers, a capability they had not previously observed. Compromising network equipment can give attackers visibility into other devices connected to the same network and potentially provide another route for accessing victims.

Some of the compromised routers are associated with countries that are members of NATO, according to Arctic Wolf.

The cybersecurity company said it identified at least 117 servers associated with LightSpy operating across several countries, suggesting that the spyware infrastructure is significantly more extensive than previously understood.

Chinese contractor linked to operation

Arctic Wolf said it was able to connect the latest LightSpy activity to a Chinese contractor after one of the spyware operators made an unusual mistake. The operator used the spyware administrator panel to place a Kentucky Fried Chicken order using their real name and office address.

The incident gave researchers a rare opportunity to connect the otherwise covert spyware operation to a specific individual and helped strengthen the link between the latest LightSpy campaign and China.

The findings illustrate how commercial spyware is increasingly moving beyond traditional state-sponsored operations, with sophisticated surveillance tools becoming available to a wider range of governments, businesses and other customers.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.