Security researchers from Arctic Wolf have uncovered that LightSpy, a Chinese-linked spyware, now threatens users in over 13 countries, including the US and several European nations. This sophisticated platform has evolved into a commercial offering, tailored for governments, enterprises and militaries alike.
The spyware's modular design allows it to infiltrate a wide array of devices—from smartphones and Apple products to Linux servers and Windows PCs—extracting sensitive data such as location, chat logs, screen recordings, and passwords. Most alarmingly, the code can remotely render devices unusable through a process known as 'bricking'.
Recently, LightSpy has been identified compromising routers, enabling attackers to surveil entire networks. Some of these compromised routers are linked to NATO member states, highlighting the spyware's potential reach and threat level.
A key revelation came when researchers traced activity back to a Chinese contractor who used an admin panel to order food from Kentucky Fried Chicken using his real name and office address. This detail suggests the spyware may be operated by individuals with direct ties to China’s state-backed hacking apparatus.
LightSpy operates from at least 117 servers worldwide, indicating its extensive network. As this surveillance tool grows in capability and reach, it poses significant risks to individual privacy and national security.







