Security researchers from Arctic Wolf have uncovered evidence that the LightSpy spyware, originally linked to Chinese state-backed hackers, has evolved into a commercial platform used by a single threat actor targeting governments, enterprises, and militaries across over 13 countries, including the U.S. The spyware can steal sensitive data, brick devices, and compromise routers, providing attackers with network-wide access. Researchers identified the threat actor by linking an order placed under a real name and address to a Chinese contractor. LightSpy operates a global server network and has capabilities to exploit various devices, including smartphones, Linux servers, and Windows PCs.
Bias read (Center): The article presents factual findings about the spread and capabilities of LightSpy without overtly criticizing or praising specific governments or actors. While the subject involves national security concerns, the framing remains neutral, focusing on technical details and researcher findings rather






