DMR News

Advancing Digital Conversations

LightSpy Spyware Expands Globally With Router Hacking and Device-Wiping Tools

ByJolyen

Aug 9, 2026

LightSpy Spyware Expands Globally With Router Hacking and Device-Wiping Tools

Chinese-linked spyware known as LightSpy has expanded beyond its earlier targeting in Asia to reach victims across more than a dozen countries, according to new research from cybersecurity firm Arctic Wolf. Researchers say the surveillance platform can now compromise phones, computers and network routers while collecting sensitive data and, in some cases, remotely destroying information on infected devices.

Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov presented their latest findings at Black Hat USA this week. Their investigation describes LightSpy as having evolved from a modular espionage tool into what they call a “Surveillance-as-a-Service” platform with infrastructure spread across multiple countries.

LightSpy Now Targets Multiple Types of Devices

LightSpy was previously associated with targeted surveillance campaigns in regions including Hong Kong and Southern Asia. Earlier Arctic Wolf research found that it could steal files, location information, contacts, messages, browser histories, saved credentials and data from apps including Telegram, QQ and WeChat.

The platform has since expanded beyond smartphones and Macs to support additional operating systems and devices. Researchers said its modular design allows operators to deploy different plugins depending on the information they want to collect from a target.

Some versions can capture screen activity, record audio, execute commands and access stored passwords. Researchers also found functions capable of deleting data or otherwise rendering compromised devices unusable.

Router Implants Extend Surveillance Across Networks

One of the more significant additions is LightSpy’s ability to compromise network routers. Arctic Wolf said it identified router implants that allow operators to maintain access at the network level rather than relying solely on individual infected devices.

A compromised router can potentially give an attacker greater visibility into devices and traffic passing through the same network. Researchers said some affected routers were associated with NATO member countries.

Arctic Wolf mapped at least 72 active command-and-control servers during its investigation. The infrastructure formed part of a broader network used to manage infections and communicate with compromised systems around the world.

Researchers Say LightSpy Resembles a Commercial Platform

The researchers believe LightSpy is now operated more like a commercial surveillance product than a tool built exclusively for one government-backed hacking group. They found evidence of customer-facing features including customized branding, billing capabilities and demonstrations intended for prospective users.

That could allow different customers, potentially including government agencies, military organizations or companies, to operate surveillance campaigns through the same underlying technology.

Arctic Wolf’s earlier analysis found Chinese-language code comments and error messages that suggested the developers were native Chinese speakers. The company has historically linked LightSpy activity to suspected Chinese operators but has not established that every customer using the platform is connected to the Chinese government.

A Food Order Helped Identify an Operator

Arctic Wolf also said an operational mistake helped researchers connect the infrastructure to a Chinese contractor. During their investigation, an individual using LightSpy’s administration system reportedly placed a Kentucky Fried Chicken order using identifying information, including a real name and office address.

The researchers used that information alongside technical evidence from LightSpy’s servers to investigate the people and organizations behind the operation. Their Black Hat presentation highlighted the incident as an example of how mistakes by spyware operators can expose otherwise difficult-to-trace surveillance infrastructure.


Featured image credits: Magnific.com

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *