LightSpy Spyware Targets 13 Countries, Including US
A careless KFC order exposed China-linked LightSpy operators targeting 13 countries with advanced malware. This breach highlights state-sponsored espionage risks, prompting US sanctions and global seโฆ
China-linked LightSpy spyware was discovered targeting victims in 13 countries, including the United States, after security researchers traced a recent operation to a Chinese company. The investigation began when one of the spywareโs operators placed an order for a KFC meal using his real name and office address, a detail that allowed analysts to link the activity to a firm registered in China. The malware, which can record keystrokes, capture screenshots and exfiltrate data, was active in the first half of 2024 and reportedly infected more than 200 devices worldwide.
The incident is part of a broader trend of state-sponsored espionage that has intensified in recent years. LightSpy is believed to be a commercial offโtheโshelf tool used by Chinese intelligence agencies to harvest sensitive information from diplomats, journalists and corporate executives. The KFC order was a rare slip that exposed the operatorโs identity, a mistake that researchers say is common in the commercial cyberโcrime market where actors often use personal addresses for anonymity. The U.S. Department of Justice has already opened a probe into the operator, and the U.S. State Department has warned its citizens and businesses about the threat.
LightSpyโs capabilities include stealth persistence, encrypted commandโandโcontrol channels and the ability to bypass many commercial security products. Analysts estimate that the malware has stolen more than 10 terabytes of data, including emails, documents and credentials. In the U.S., the FBI has identified several highโprofile targets, including a former federal official and a tech company executive. The Chinese company behind the malware, which remains unnamed in public statements, is believed to have received funding from a stateโcontrolled investment fund. The U.S. Treasury has added the firm to its sanctions list, and the European Union is considering similar measures.
The fallout will likely involve tighter export controls on cybersecurity tools and a push for better crossโborder cooperation on cyberโcrime. Lawโenforcement agencies in the U.S., China, the U.K. and other affected nations are coordinating to trace the malwareโs command servers and shut down the supply chain. In the meantime, cybersecurity firms are updating detection signatures and advising organizations to monitor for signs of LightSpy activity. The incident underscores the growing risk of commercial spyware in the hands of state actors and the need for robust defensive measures across industries.
Read Full Story at TechCrunch โ

