Chinese LightSpy Spyware Targets US and NATO Allies – Claril Noticias

Cybersecurity researchers at Arctic Wolf revealed this week that LightSpy, a sophisticated spyware platform linked to China, has expanded its operations to target victims in 13 countries—including the UK, US, and NATO members—by exploiting routers and device vulnerabilities to harvest sensitive data and remotely destroy compromised systems.

From State-Backed Malware to Commercial Espionage

Initially discovered in 2018 and linked to Chinese state-backed threat actors, the LightSpy spyware has evolved significantly. According to analysts at cybersecurity firm Arctic Wolf, the malware has transitioned into a fully commercialised spyware platform. This sophisticated operation is now run by a single threat actor catering to governments, military organisations, and corporate enterprises globally.

The commercialised platform features bespoke branding, tailored billing systems, and product demonstrations designed to attract prospective clients. This development highlights a worrying trend: the proliferation of highly invasive spyware beyond state intelligence agencies and into the broader private sector.

How LightSpy Infiltrates and Bricks Devices

LightSpy is a highly versatile, modular spyware platform. Its architecture allows operators to deploy specific exploits tailored to a wide range of operating systems, including smartphones, Apple devices, Linux servers, and Windows PCs. Once inside, the spyware extracts vast amounts of sensitive data, including real-time location tracking, encrypted chat messages, screen recordings, and saved credentials.

Beyond espionage, the latest iteration of LightSpy introduces destructive capabilities. Researchers discovered that the malware now contains code enabling operators to remotely wipe and brick compromised devices, completely destroying stored data.

The Router Threat and NATO Targets

In a significant tactical shift, researchers detected LightSpy infecting network routers for the first time. By compromising a router, attackers gain a strategic foothold, allowing them to monitor and intercept traffic from every device connected to that specific network.

Several of these compromised routers are linked to NATO member states, raising serious national security concerns. To support this global campaign, the operators of LightSpy maintain an active infrastructure of at least 117 command-and-control servers distributed across multiple countries.

The KFC Blunder: How the Hackers Were Exposed

Despite the high sophistication of the malware, the operation suffered a critical operational security failure. Researchers successfully linked the recent cyber campaigns to a Chinese contractor after one of the spyware operators used the active LightSpy administrator panel to order a meal from Kentucky Fried Chicken (KFC), inadvertently exposing his real name and physical office address.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *