Home / Technology

Photo of person at computer, cryptocurrency, television
Image: via techcrunch.com
Technology

Global Spyware Targeting 13 Countries, Including US and EU

WireByte Staff · August 7, 2026

Security researchers have discovered a Chinese-linked spyware, LightSpy, targeting victims in 13 countries, including the US and EU. The spyware, first identified in 2018, has evolved into a commercial platform operated by a single threat actor, catering to governments, enterprises, and militaries. It can steal sensitive information, remotely wipe devices, and is now infecting routers.

Key points

  • LightSpy, a Chinese-linked spyware, has expanded to target victims in 13 countries, including the US and EU.
  • The spyware, first discovered in 2018, has evolved into a commercial platform operated by a single threat actor.
  • The platform allows the threat actor to target multiple devices, including smartphones, Apple devices, and Windows PCs.
  • LightSpy can steal sensitive information, including location data, chat messages, and stored passwords.
  • The spyware is now capable of remotely wiping and destroying data on compromised devices.

Security researchers have uncovered a significant expansion of a Chinese-linked spyware, LightSpy, which is now targeting victims in 13 countries, including the US and several European nations. This development highlights the growing threat of spyware beyond nation-backed hackers and into the private industry.

The researchers at Arctic Wolf, a cybersecurity firm, first identified LightSpy in 2018, linking it to Chinese state-backed hackers. However, the latest findings indicate that the spyware has evolved into a commercial platform operated by a single threat actor. This actor caters to governments, enterprises, and militaries, offering custom branding, billing, and demos for advertising the platform to prospective customers.

LightSpy is a modular spyware platform that allows the threat actor to target a multitude of devices, including smartphones, Apple devices, Linux servers, and Windows PCs. By exploiting vulnerabilities in each device, the spyware can steal large amounts of sensitive information, including precise location data, chat messages, screen recordings, and stored passwords. Furthermore, the code is capable of remotely wiping and destroying data on compromised devices.

The researchers have also discovered that LightSpy has now begun infecting routers, further expanding its capabilities and reach. This development underscores the growing threat of spyware and the need for enhanced cybersecurity measures to protect individuals and organizations from these threats.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.