mimile
Back to feed

Arctic Wolf Exposes Chinese-Linked LightSpy Spyware in Over 13 Nations

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Arctic Wolf Exposes Chinese-Linked LightSpy Spyware in Over 13 Nations

Cybersecurity firm Arctic Wolf Networks has linked the LightSpy spyware to Chinese state-backed actors, active in more than 13 countries. The malware collects location data, audio, chat logs, camera feeds, and can remotely wipe devices. Its infrastructure spans 117 servers, with a focus on European and African routers, while Beijing has yet to comment.

The LightSpy Toolkit

LightSpy implants can seize location data, ambient audio, messaging histories, camera images, and screenshots from compromised devices. Researchers at Arctic Wolf report the malware grants full control over infected handsets, including the ability to remotely wipe personal data. Originally detected in mainland China roughly four years ago, the tool has since evolved into a modular surveillance platform offered on a subscription basis, according to details cited by The Straits Times.

Infrastructure and Geographic Spread

The operation now extends beyond China to routers across Europe and Africa, using 117 servers to relay stolen data. Arctic Wolf found that LightSpy’s user base includes Chinese commercial enterprises, government bodies, military structures, and educational institutions. The platform’s expansion—to more than 13 countries—was achieved by planting malicious code on network routers, allowing persistent access to sensitive information.

What's Next

Arctic Wolf has shared its full findings with the U.S. Department of Homeland Security and the FBI. It remains unclear whether Beijing will issue a formal response or if affected nations will move to disrupt the server infrastructure.

1 source

Arctic Wolf Exposes Chinese-Linked LightSpy Spyware in Over 13 Nations