First discovered in 2018, LightSpy has transitioned from a state-backed hacking tool into a commercial suite marketed to governments and private enterprises with custom branding and billing features. The malware now targets a broad spectrum of hardware, including Windows PCs, Linux servers, and Apple devices, exfiltrating sensitive data such as chat logs, passwords, and precise geolocation.
Security analysts report that the software’s capabilities now include remote device destruction and, notably, the infection of routers. By compromising these network entry points, operators gain visibility into every connected device within a household or office. Arctic Wolf confirmed that several infected routers are located within NATO member countries, supported by a global infrastructure of at least 117 command-and-control servers. The investigation led to a definitive attribution after a careless administrator accessed the spyware’s control panel to place a food delivery order, inadvertently exposing his real name and office address in China.
Comments (0)
No comments yet. Be the first!