China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

The LightSpy spyware, previously linked to Chinese state-backed actors, has evolved into a commercial platform targeting devices in 13 countries. It now features advanced capabilities like infecting routers and remotely destroying data.
Why it matters
The commercialization of sophisticated spyware poses a growing threat to global privacy and national security infrastructure.
Security researchers say they have evidence that a Chinese-linked spyware has expanded from mainland China to now target victims in over a dozen countries, including across Europe and the United States. The previously identified spyware also has new functionality capable of stealing troves of data and remotely bricking devices.
The researchers at cybersecurity firm Arctic Wolf said that the LightSpy spyware, first discovered in 2018 and previously linked to Chinese state-backed hackers, has since evolved into a commercial spyware platform operated by a single threat actor who caters to governments, enterprises, and militaries.
The platform is said to feature custom branding, billing, and demos for advertising it to prospective customers.
The findings underscore how the use of spyware continues to proliferate beyond governments and nation-backed hackers, and more broadly into the private industry.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in