China-Linked LightSpy Targets 13 Countries, Adds Router Attacks
Arctic Wolf says China-linked LightSpy targets 13 countries through 117 servers, stealing data, compromising routers and remotely destroying victim devices.
Summary
TechCrunch reported on August 6, 2026, that Arctic Wolf found China-linked LightSpy infecting victims in 13 countries, expanding beyond mainland China into Europe and the United States. First discovered in 2018 and previously tied to Chinese state-backed hackers, the modular spyware has evolved into a commercial platform run by one threat actor for governments, enterprises and militaries, with custom branding, billing and sales demonstrations.
LightSpy uses device-specific exploits against smartphones, Apple devices, Linux servers and Windows PCs to extract precise locations, chat messages, screen recordings and stored passwords, while new functions can remotely wipe data and brick compromised devices. Arctic Wolf also identified the first known router infections, which can expose other devices on the same network, including compromised routers associated with NATO member countries. The operation uses at least 117 servers across several countries. Researchers linked the latest activity to a Chinese contractor after an operator ordered Kentucky Fried Chicken through LightSpy’s administrator panel using his real name and office address, highlighting commercial spyware’s spread beyond governments and state-backed groups into private industry.
Positives
- Arctic Wolf mapped at least 117 LightSpy servers across several countries, revealing substantial operational infrastructure.
- A Kentucky Fried Chicken order exposed an operator’s real name and office address, helping researchers link the latest activity to a Chinese contractor.
- Arctic Wolf identified LightSpy’s previously unseen router infections, documenting a significant expansion of the platform’s capabilities.
Risks & concerns
- LightSpy now targets victims in 13 countries, reaching Europe and the United States after its earlier concentration in mainland China.
- LightSpy can steal precise locations, chat messages, screen recordings and stored passwords, then remotely wipe data or brick compromised devices.
- Router infections give operators visibility and access to other devices sharing the compromised network.
- Some compromised routers are associated with NATO member countries, extending the campaign into security-sensitive networks.
- Custom branding, billing and demonstrations position LightSpy as a commercial product for governments, enterprises and militaries.