Technology

A Spyware Tool Called LightSpy Is Now for Sale — and It's Hitting 13 Countries

Martin HollowayPublished 2d ago4 min readBased on 5 sources
Reading level
A Spyware Tool Called LightSpy Is Now for Sale — and It's Hitting 13 Countries

Cybersecurity firm Arctic Wolf disclosed on August 5, 2026, that a spyware tool called LightSpy is actively targeting victims across 13 countries, including nations in Europe and the United States. The findings reveal that LightSpy has shifted from its origins as a tool linked to Chinese government-backed hackers into a commercial spyware business — one that sells its spying capabilities to governments, companies, and militaries.

LightSpy was first discovered in 2018. It was previously associated with Chinese state-sponsored hackers. According to Arctic Wolf's analysis, the platform is now run by a single operator who treats it as a business, complete with custom branding, billing systems, and product demos offered to prospective customers. The shift from a government intelligence tool to a paid service follows a broader trend in the spyware market, where powerful capabilities once reserved for nations are increasingly sold to anyone who can pay.

What LightSpy Can Do

The platform works across many types of devices. It can compromise smartphones, Apple devices, Linux servers, and Windows PCs. Once a device is infected, LightSpy can secretly steal precise location data, chat messages, screen recordings, and stored passwords. The software can also remotely wipe and destroy data on a compromised device — a destructive feature that sets it apart from tools focused only on spying and aligns it with tools designed to disrupt operations.

Arctic Wolf identified a new capability not previously documented in LightSpy's history: infection of routers, the devices that direct internet traffic between networks. Some of the compromised routers are associated with NATO member countries. Compromising routers extends LightSpy's reach beyond individual phones and computers into the infrastructure that connects them, where the spyware can stay hidden, intercept traffic, and maintain access even if an infected device is cleaned.

A Global Network and a Careless Mistake

The spyware runs on a network of at least 117 servers spread across several countries. This setup supports the platform's business model, where multiple customers likely purchase access to the spying tools backed by shared infrastructure.

Arctic Wolf traced the latest LightSpy campaign to a Chinese contractor because of a mistake by one of the platform's own operators. An individual used LightSpy's administrator panel to place an order with Kentucky Fried Chicken, providing a real name and office address in the process. That identifying information allowed Arctic Wolf to link the activity to a Chinese contractor.

Earlier Reporting

Earlier reporting adds context to LightSpy's development. In March 2026, Reuters reported that researchers had uncovered a powerful software exploit capable of penetrating and stealing information from potentially hundreds of millions of Apple iPhones. ThreatFabric published its own analysis in October 2024, finding that the LightSpy tool for iOS also targets macOS and has evolved new destructive features over time.

The evolution from a niche iPhone tool to a multi-platform, router-infecting commercial platform with paying customers raises questions about how commercial spyware providers should be regulated. The KFC ordering incident is a useful reminder that even sophisticated operators make basic mistakes, but it is a single lead, not a lasting obstacle to the platform's continued operation. With 117 servers, a billing system, and documented router compromises near NATO networks, LightSpy is operating at a scale that invites comparison to the NSO Group controversy of the early 2020s, though the geopolitical dynamics differ given the China connection.

What This Means for Security Teams

For security teams, the practical takeaways are concrete. Router-level compromise means that focusing detection only on individual phones and computers is not enough; monitoring network infrastructure and checking router software for tampering become necessary. The cross-platform design means that no single operating system can be assumed safe. And the commercial model means the threat is no longer limited to one government's intelligence service — any paying customer with sufficient motivation may be operating LightSpy against targets in the 13 identified countries, or beyond.

Arctic Wolf publicly disclosed its findings on August 5, 2026. Bloomberg and the Insurance Journal reported on the disclosure.