Urgent.News

What's breaking now, across thousands of outlets.

Tech

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.

Security researchers have uncovered evidence of a Chinese-linked spyware, LightSpy, expanding its reach to target victims in over a dozen countries, including the United States. Originally discovered in 2018 and previously linked to Chinese state-backed hackers, LightSpy has evolved into a commercial spyware platform. The platform, run by a single threat actor, offers custom branding, billing, and demos to attract clients from governments, enterprises, and militaries.

LightSpy is a modular spyware capable of attacking various devices, including smartphones, Apple devices, Linux servers, and Windows PCs. By exploiting each device, the spyware can steal sensitive information, such as precise location data, chat messages, screen recordings, and stored passwords. The researchers found that LightSpy has been identified infecting routers for the first time, enabling hackers to gain visibility and access to any device on the same network. Some compromised routers belong to NATO member countries.

The spyware operates a network of at least 117 servers in various countries. Researchers traced the latest activity to a Chinese contractor after observing an instance where the spyware's operator placed an order using his real name and office address on Kentucky Fried Chicken's website, placing the order through LightSpy's administrator panel.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in Tech

More from Thursday 6 August →