Skip to content
SecurityTech

State-grade spyware goes commercial, operator orders KFC through admin panel with real name

Security researchers at Arctic Wolf report that the China-linked LightSpy spyware has expanded from mainland China to target victims in 13 countries, including the US and NATO members. Originally discovered in 2018, the modular platform has evolved into a commercial spyware-as-a-service offering with custom branding, billing, and demos for government and enterprise customers. New capabilities include router compromise for network-wide visibility, remote device bricking, and data theft across smartphones, Apple devices, Linux servers, and Windows PCs. Researchers linked the activity to a Chinese contractor after an operator used the spyware's admin panel to order KFC using his real name and office address.

Read full article →