#LightSpy
New #LightSpy #Spyware Version Targets #iPhones with Increased #Surveillance Tactics

"The plugins can capture a wide range of data, including Wi-Fi network information, screenshots, location, iCloud Keychain, sound recordings, photos, browser history..."
thehackernews.com/2024/10/new-...
New LightSpy Spyware Version Targets iPhones with Increased Surveillance Tactics
Discover the latest LightSpy iOS spyware, featuring expanded capabilities and destructive functions.
thehackernews.com
November 9, 2024 at 8:40 PM
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.
techcrunch.com
August 6, 2026 at 7:25 PM
Researchers uncover a revamped LightSpy spyware with over 100 commands, targeting Android, iOS, Windows, macOS, and platforms like Facebook and Instagram. #spyware #CyberAlerts thehackernews.com/2025/02/ligh...
LightSpy Expands to 100+ Commands, Increasing Control Over Windows, macOS, Linux, and Mobile
LightSpy malware now supports 100+ commands across platforms, targeting Facebook and Instagram data while expanding operational control.
thehackernews.com
February 25, 2025 at 10:02 PM
@volexity.bsky.social has published a blog post detailing variants of LIGHTSPY & DEEPDATA malware discovered in the summer of 2024, including exploitation of a vulnerability in FortiClient to extract credentials from memory. Read more here: www.volexity.com/blog/2024/11...
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
In July 2024, Volexity identified exploitation of a zero-day credential disclosure vulnerability in Fortinet’s Windows VPN client that allowed credentials to be stolen from the memory of the client’s ...
www.volexity.com
November 15, 2024 at 8:02 PM
New LightSpy spyware variant comes with enhanced data collection features targeting social media platforms
New LightSpy spyware variant comes with enhanced data collection features targeting social media platforms
Researchers found an updated LightSpy spyware with enhanced data collection features targeting social media platforms(Facebook, Instagram).
securityaffairs.com
February 26, 2025 at 10:30 AM
>> Spyware auf Routern
Chinesische Spionageangriffe auf Europa aufgedeckt

www.golem.de/news/spyware...
Spyware auf Routern: Chinesische Spionageangriffe auf Europa aufgedeckt - Golem.de
Forscher konnten die Lightspy-Spyware zu einem chinesischen Unternehmen zurückverfolgen. Aufgeflogen ist dieses wohl wegen einer KFC-Bestellung.
www.golem.de
August 7, 2026 at 8:39 PM
-Malware reports on TgToxic Android banker, Anubis, PolarEdge botnet
-Mirai botnet linked to brute-force attacks
-New Auto-color backdoor targets Linux
-Truesight EDR killer campaign spotted in the wild
-APT reports on Erudite Mogwai, LightSpy, Mustang Panda, ReaverBits, Sandworm, and Ghostwriter
February 26, 2025 at 9:20 AM
LightSpy Expands to 100+ Commands, Increasing Control Over Windows, macOS, Linux, and Mobile reconbee.com/lightspy-exp...

#lightspy #windows #macOS #linux #CyberSecurity #cybersecuritynews
LightSpy Expands to 100+ Commands Increasing Control Over Windows macOS Linux and Mobile
compatible plugins read more about LightSpy Expands to 100+ Commands Increasing Control Over Windows macOS Linux and Mobile
reconbee.com
February 26, 2025 at 7:28 AM
"Wi-Fi network configuration profiles, contacts, and browser history, and even freeze the device and prevent it from starting again. Furthermore, LightSpy plugins can generate fake push notifications containing a specific URL."
November 9, 2024 at 8:41 PM
The China-linked APT actor behind the LightSpy iOS malware has expanded its toolset with a Windows-based surveillance framework, BlackBerry reports. www.securityweek.com/lightspy-ios...
LightSpy Spyware Operation Expands to Windows
The Chinese APT behind the LightSpy iOS backdoor has expanded its toolset with DeepData, a modular Windows-based surveillance framework.
www.securityweek.com
November 15, 2024 at 1:26 PM
LightSpy Spyware Expands Its Reach: New Commands and Enhanced Data Harvesting on Multiple Platforms

Cybersecurity researchers have recently uncovered an upgraded version of the LightSpy implant, a powerful modular spyware targeting a wide range of operating systems including Windows, macOS, Linux,…
LightSpy Spyware Expands Its Reach: New Commands and Enhanced Data Harvesting on Multiple Platforms
Cybersecurity researchers have recently uncovered an upgraded version of the LightSpy implant, a powerful modular spyware targeting a wide range of operating systems including Windows, macOS, Linux, and mobile devices. First documented in 2020, LightSpy has continually evolved, adding new capabilities to increase its data harvesting prowess. With its latest iteration, LightSpy now includes more than 100 commands, significantly boosting its control over infected systems.
undercodenews.com
March 1, 2025 at 12:38 PM
Recent Version of LightSpy iOS Malware Packs Destructive Capabilities
Recent Version of LightSpy iOS Malware Packs Destructive Capabilities
A newer version of the LightSpy malware for iOS includes over a dozen new plugins, many with destructive capabilities.
buff.ly
November 1, 2024 at 9:42 PM
Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users
Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users
A sophisticated cyber-espionage campaign has re-emerged, targeting South Asia with an iOS spyware implant called LightSpy.
thehackernews.com
April 15, 2024 at 9:18 AM
Experts found a macOS version of the sophisticated LightSpy spyware
Experts found a macOS version of the sophisticated LightSpy spyware
Researchers spotted a macOS version of the LightSpy surveillance framework that has been active in the wild since at least January 2024.
securityaffairs.com
May 30, 2024 at 7:17 PM
macOS version of elusive 'LightSpy' spyware tool discovered
macOS version of elusive 'LightSpy' spyware tool discovered
A macOS version of the LightSpy surveillance framework has been discovered, confirming the extensive reach of a tool only previously known for targeting Android and iOS devices.
www.bleepingcomputer.com
May 30, 2024 at 11:23 AM
3️⃣ LightSpy | Evolves from Mobile to macOS

In 2024, researchers discovered a macOS version of LightSpy, complete with macOS specific plugins for a suite of surveillance and control tasks, with an apparent focus on targets in India.
January 20, 2025 at 5:11 PM
LightSpy Expands to 100+ Commands, Increasing Control Over Windows, macOS, Linux, and Mobile Cybe […]

[Original post on ihash.eu]
Original post on ihash.eu
www.ihash.eu
February 27, 2025 at 1:07 AM
LightSpy Expands to 100+ Commands, Increasing Control Over Windows, macOS, Linux, and Mobile Cybe […]

[Original post on ihash.eu]
Original post on ihash.eu
www.ihash.eu
February 27, 2025 at 1:32 PM
LightSpy Expanded With 100+ Commands to Attack Android, iOS, Windows, macOS & Linux Users
LightSpy Expanded With 100+ Commands to Attack Android, iOS, Windows, macOS & Linux Users
The LightSpy advanced persistent threat (APT) group has significantly upgraded its surveillance capabilities with a 100+ command framework targeting Android, iOS, Windows, macOS, and Linux systems, according to new infrastructure analysis.  This modular malware now employs refined data exfiltration techniques against social media platforms and expanded device control mechanisms, marking a strategic shift toward omnidirectional cyberespionage. Screenshot of current servers tagged as LightSpy Evolution of LightSpy’s Command Infrastructure According to Hunt.io Report , Threat Hunting Platform, the latest command-and-control (C2) server at 149.104.18[.]80:10000 reveals a 182% increase in supported operations compared to the previously documented 45.125.34[.]126:49000 server, which hosted 55 commands.  The updated cmd_list endpoint (/ujmfanncy76211/front_api) introduces granular control mechanisms like 传输控制 (“transmission control”) and 上传插件版本详细信息 (“upload plugin version details”), enabling operators to manage compromised devices through version-aware plugin deployments. Notably, the framework now targets Facebook and Instagram database files through dedicated Android commands: Command ID 83001: 获取Facebook数据库文件 (“Get Facebook Database Files”) Command ID 83002: 获取Instagram数据库文件 (“Get Instagram Database Files”) This represents LightSpy’s first known integration of social media database extraction, potentially exposing private messages, contact lists, and authentication tokens stored in SQLite databases. Windows Surveillance Plugins and System Integration Analysis of the 149.104.18[.]80 server’s port 40002 endpoint uncovered 15 Windows-specific DLL plugins designed for x86/x64 architectures. These components exhibit surveillance capabilities through: KeyLogLib32m.dll/KeyLogLib64m.dll: Kernel-level keystroke logging audiox64m.dll/audiom.dll: System audio capture via Windows Audio Session API (WASAPI) video64m.dll/videom.dll: Desktop duplication API-based screen recording The plugins follow a development pattern evidenced by PDB paths like W:\yk\Bigfoot\bin*.pdb, suggesting compartmentalized project structures.  Version numbering (0.0.0.0-0.0.0.2) indicates active development cycles, with “Terminal” plugins likely hooking into Windows Console API for command execution monitoring. LightSpy’s infrastructure employs multi-port C2 channels across: Port 30000: iOS core version management (light.framework.zip) Port 40002: Windows plugin distribution Port 10000: Admin panel authentication (/ujmfanncy76211/login) The framework’s Vue.js-based admin interface (Console v3.5.0) was briefly exposed through a misconfigured /third_login/:username endpoint, revealing device grouping capabilities and real-time terminal log access.  Forensic artifacts from the 2021-12-31 core version (MD5:81d2bd4781e3753b508ff6d966dbf160) show improved session persistence mechanisms compared to the 2020-12-21 build. Mitigation Strategies for Enterprise Defense Organizations should implement: iOS Lockdown Mode: Restricts attack surfaces by disabling Just-in-Time (JIT) JavaScript compilation Android Enhanced Play Protect: Scans sideloaded APKs for LightSpy’s signature WASM-based payloads Windows Memory Integrity Checks: Blocks unsigned drivers like KeyLogLib64m.dll through Hypervisor-protected Code Integrity (HVCI) Network defenders can detect LightSpy’s TLS fingerprint (JA3:6734f37431670b3ab4292b8f60f29984) and monitor for anomalous requests to /963852741/ios/version.json endpoints. The framework’s expanded command set enables threat actors to: Chain database extraction (Commands 83001-83002) with MITM attacks using rogue CA certificates Correlate social media metadata with geolocation data from Capx64m.dll’s screenshot capabilities Establish persistence through USB device emulation via usbx64m.dll This development positions LightSpy as a polymorphic threat capable of bridging OS-specific vulnerabilities into cross-platform intrusion campaigns.  Given their role in plugin distribution and C2 operations, continued monitoring of Cloudie Limited-hosted IPs (103.238.227[.]138, 43.248.8[.]108) is critical. Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response and Threat Hunting –  Register Here The post LightSpy Expanded With 100+ Commands to Attack Android, iOS, Windows, macOS & Linux Users appeared first on Cyber Security News .
cybersecuritynews.com
February 25, 2025 at 12:19 PM
🔍 What can fried chicken receipts reveal about a global surveillance operation?🍗

72 servers. Router implants. One OPSEC mistake.

See how researchers unraveled the LightSpy surveillance operation in this #BHUSA 2026 Briefing.

Learn more: https://bit.ly/4feMsxs
July 5, 2026 at 10:52 PM