Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

LightSpy Spyware Targets 13 Countries, Including US

A careless KFC order exposed China-linked LightSpy operators targeting 13 countries with advanced malware. This breach highlights state-sponsored espionage risks, prompting US sanctions and global seโ€ฆ

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
TechCrunch โ€” 6 August 2026
Text:
12 0 0

China-linked LightSpy spyware was discovered targeting victims in 13 countries, including the United States, after security researchers traced a recent operation to a Chinese company. The investigation began when one of the spywareโ€™s operators placed an order for a KFC meal using his real name and office address, a detail that allowed analysts to link the activity to a firm registered in China. The malware, which can record keystrokes, capture screenshots and exfiltrate data, was active in the first half of 2024 and reportedly infected more than 200 devices worldwide.

The incident is part of a broader trend of state-sponsored espionage that has intensified in recent years. LightSpy is believed to be a commercial offโ€‘theโ€‘shelf tool used by Chinese intelligence agencies to harvest sensitive information from diplomats, journalists and corporate executives. The KFC order was a rare slip that exposed the operatorโ€™s identity, a mistake that researchers say is common in the commercial cyberโ€‘crime market where actors often use personal addresses for anonymity. The U.S. Department of Justice has already opened a probe into the operator, and the U.S. State Department has warned its citizens and businesses about the threat.

LightSpyโ€™s capabilities include stealth persistence, encrypted commandโ€‘andโ€‘control channels and the ability to bypass many commercial security products. Analysts estimate that the malware has stolen more than 10 terabytes of data, including emails, documents and credentials. In the U.S., the FBI has identified several highโ€‘profile targets, including a former federal official and a tech company executive. The Chinese company behind the malware, which remains unnamed in public statements, is believed to have received funding from a stateโ€‘controlled investment fund. The U.S. Treasury has added the firm to its sanctions list, and the European Union is considering similar measures.

The fallout will likely involve tighter export controls on cybersecurity tools and a push for better crossโ€‘border cooperation on cyberโ€‘crime. Lawโ€‘enforcement agencies in the U.S., China, the U.K. and other affected nations are coordinating to trace the malwareโ€™s command servers and shut down the supply chain. In the meantime, cybersecurity firms are updating detection signatures and advising organizations to monitor for signs of LightSpy activity. The incident underscores the growing risk of commercial spyware in the hands of state actors and the need for robust defensive measures across industries.

Read Full Story at TechCrunch โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Alonso pleased with Aston Martin upgrade as Newey targets 'โ€ฆ
๐Ÿ’ป Technology
Alonso pleased with Aston Martin upgrade as Newey targets 'respectability'
Sky Sports ยท 13 days ago
Apple announces Siloโ€™s season 4 return date
๐Ÿ’ป Technology
Apple announces Siloโ€™s season 4 return date
9to5Mac ยท 10 days ago
Anthropic upgrades Claude with new Opus 5 model, details heโ€ฆ
๐Ÿ’ป Technology
Anthropic upgrades Claude with new Opus 5 model, details here
9to5Mac ยท 13 days ago
Why Tesla Stock Crashed Today
๐Ÿ“ˆ Markets & Finance
Why Tesla Stock Crashed Today
Nasdaq News ยท 14 days ago
Hereโ€™s the biggest news you missed this weekend
๐ŸŒ World News
Hereโ€™s the biggest news you missed this weekend
NBC News ยท 11 days ago
Singapore Stock Market Tipped To Open In The Red
โš”๏ธ War & Conflict
Singapore Stock Market Tipped To Open In The Red
Nasdaq News ยท 14 days ago
Full view