A spyware platform previously confined to mainland China has quietly expanded its reach across more than a dozen countries, with new capabilities that allow operators to steal vast troves of data or remotely destroy compromised devices. Researchers at cybersecurity firm Arctic Wolf have documented this evolution, revealing that LightSpy, first identified in 2018, has transformed into a commercial-grade surveillance tool with a single operator catering to governments, militaries, and private enterprises. Main Developments Arctic Wolf's investigation shows LightSpy now operates a network of at least 117 servers spread across multiple countries, marking a substantial infrastructure expansion. The spyware has been observed infecting routers for the first time, a development that gives attackers visibility into every device connected to a compromised network. Some of these routers belong to NATO member nations, according to the researchers. The platform's modular design allows operators to target smartphones, Apple devices, Linux servers, and Windows PCs using device-specific exploits. Once deployed, LightSpy can extract precise location data, chat messages, screen recordings, and stored passwords. The code also includes functionality to remotely wipe and destroy data on compromised systems. Read also: Hadrian Secures $1.37B to Automate Military Manufacturing Researchers linked the latest campaign to a Chinese contractor after an operator using the LightSpy administration panel placed an order with Kentucky Fried Chicken using their real name and office address. This operational security lapse provided a direct connection between the spyware activity and a specific individual. Background LightSpy was first discovered in 2018 and has historically been attributed to Chinese state-backed hacking groups. The platform's earlier iterations were primarily focused on targets within mainland China, with researchers tracking its development over several years. The shift toward a commercial model represents a notable departure from its origins as a state-sponsored tool. Arctic Wolf's findings indicate that LightSpy now functions as a commercial spyware platform featuring custom branding, billing systems, and promotional demos designed to attract prospective customers. This business-oriented approach mirrors a broader trend in the surveillance industry, where sophisticated hacking tools are increasingly marketed to non-state actors. Why It Matters The expansion of LightSpy into 13 countries signals that spyware proliferation is no longer limited to governments and nation-backed hackers. Private industry players, including enterprises and potentially other commercial entities, now have access to capabilities once reserved for intelligence agencies. The new router-targeting functionality raises particular concerns because it enables network-level surveillance, potentially compromising entire organizations rather than individual devices. For victims in NATO countries and elsewhere, the threat extends beyond data theft to include destructive attacks that can render devices inoperable. What's Next Arctic Wolf's research provides a detailed technical picture of LightSpy's current capabilities, but questions remain about the full scope of its operations. The identification of at least 117 servers suggests ongoing infrastructure management, and the commercial model implies continued efforts to attract new customers. Security teams and network administrators in affected regions will likely need to assess whether their routers show signs of compromise and monitor for indicators of LightSpy activity. The researchers' findings may also prompt further investigation into the Chinese contractor identified through the operational security lapse.