Chinese Spyware LightSpy Operates in 13 Countries, Cyber Firm Reports
Article Content
- •LightSpy spyware tool operates in 13 countries, linked to Chinese state actors.
- •The platform allows extensive data theft, including location and audio recordings.
- •Arctic Wolf Networks is collaborating with U.S. authorities for further investigation.
A Chinese spyware tool named LightSpy has been identified as a significant surveillance technology operating in at least 13 countries. According to Arctic Wolf Networks, LightSpy allows users to steal sensitive personal information, including location data, audio recordings, and more. The platform features a commercial model with pricing tiers and a demo environment for potential buyers. It is linked to Chinese state actors and is currently being investigated by U.S. authorities, including the Department of Homeland Security and the FBI. LightSpy has been active for several years, with its infrastructure expanding to 117 servers worldwide, enabling data interception across Europe and Africa. The tool's capabilities pose risks for monitoring and suppressing opposition voices globally.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track LightSpy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…