Arctic Wolf Exposes Chinese-Linked LightSpy Spyware in Over 13 Nations
This digest was compiled by AI from multiple sources — links to the originals are below.

Cybersecurity firm Arctic Wolf Networks has linked the LightSpy spyware to Chinese state-backed actors, active in more than 13 countries. The malware collects location data, audio, chat logs, camera feeds, and can remotely wipe devices. Its infrastructure spans 117 servers, with a focus on European and African routers, while Beijing has yet to comment.
The LightSpy Toolkit
LightSpy implants can seize location data, ambient audio, messaging histories, camera images, and screenshots from compromised devices. Researchers at Arctic Wolf report the malware grants full control over infected handsets, including the ability to remotely wipe personal data. Originally detected in mainland China roughly four years ago, the tool has since evolved into a modular surveillance platform offered on a subscription basis, according to details cited by The Straits Times.
Infrastructure and Geographic Spread
The operation now extends beyond China to routers across Europe and Africa, using 117 servers to relay stolen data. Arctic Wolf found that LightSpy’s user base includes Chinese commercial enterprises, government bodies, military structures, and educational institutions. The platform’s expansion—to more than 13 countries—was achieved by planting malicious code on network routers, allowing persistent access to sensitive information.
What's Next
Arctic Wolf has shared its full findings with the U.S. Department of Homeland Security and the FBI. It remains unclear whether Beijing will issue a formal response or if affected nations will move to disrupt the server infrastructure.
1 source
Arctic Wolf Exposes Chinese-Linked LightSpy Spyware in Over 13 Nations



