A spyware platform linked to China has reportedly expanded well beyond mainland China, with security researchers identifying LightSpy activity across 13 countries, including the United States and several European nations.
The malware has also gained new capabilities that can collect sensitive information and remotely disable compromised devices.
Cybersecurity firm Arctic Wolf says LightSpy, first identified in 2018 and previously associated with Chinese state-backed hackers, now appears to operate as a commercial spyware platform. Researchers believe a single threat actor runs the operation and provides the spyware to governments, businesses, and military customers.

Instagram | moneyandbanking.th | Researchers report LightSpy is now distributed commercially to high-profile clients by a single operator.
The platform reportedly includes custom branding, billing systems, and product demonstrations designed for potential buyers. That development points to a wider shift in how advanced surveillance tools are being distributed beyond traditional government operations.
LightSpy uses a modular design that lets operators target different types of devices. Researchers have identified versions capable of attacking smartphones, Apple devices, Linux servers, and Windows PCs. Once installed, the spyware can collect location information, chat messages, screen recordings, and stored passwords.
The software can also remotely wipe or destroy data, giving attackers control that goes well beyond simple information theft.
Routers Become New Targets
Arctic Wolf researchers also found LightSpy infecting routers, something they had not previously observed with the spyware. A compromised router can provide attackers with visibility into other devices connected to the same network.
Some affected routers are linked to NATO member countries. Arctic Wolf estimates that the LightSpy operation currently uses at least 117 servers spread across multiple countries.

Instagram | the.tech.haven | LightSpy has been detected on routers for the first time, giving hackers visibility into local network traffic.
Researchers also traced recent activity to a Chinese contractor after an operator allegedly used the LightSpy administrator panel to order Kentucky Fried Chicken using his real name and office address.
The expansion of LightSpy shows how spyware can create risks across phones, computers, servers, and entire networks. Its ability to steal private data, monitor devices, compromise routers, and destroy information makes the platform a significant cybersecurity concern.
The latest LightSpy findings suggest that the spyware has moved into a broader international market. Its growing device support, network reach, and commercial operation make continued monitoring important for organizations and individuals handling sensitive information.



