Target Industry

Indiscriminate, opportunistic targeting. 

Overview

Cyber security researchers from Hunt.io have discovered that LightSpy now supports over a hundred commands targeting multiple operating systems, enhancing its data collection and device control capabilities. LightSpy, a sophisticated spyware framework initially discovered in 2020, can now extract data from social media platforms. 

Impact

The LightSpy spyware poses a significant threat due to its advanced capabilities and wide range of targets. It can extract sensitive data from social media platforms, including private messages, contact lists, and personal documents, and steal files from applications like WhatsApp. The spyware can also record audio, capture screen activity, and track the device’s location, leading to severe privacy breaches. 

Exploitation

The spyware exploits known vulnerabilities to gain initial access and escalates privileges using jailbreak techniques. The new commands are designed to extract database files from social media platforms on Android, Apple, and Windows operating systems. It also has the capacity to retrieve user KeyChain data, device lists, and execute shell commands. 

The new iOS version (7.9.0) of the spyware includes plugins that can interfere with the device’s startup process. If a device is infected with this version of the spyware, these plugins can prevent the device from booting up properly, effectively rendering it unusable. 

Containment, Mitigations & Remediations

To mitigate against LightSpy spyware, it is recommended that organisations: 

  • Keep all devices’ software updated to patch known vulnerabilities 
  • Back up devices regularly to an external drive or cloud storage 
  • Monitor network traffic to detecting unusual traffic patterns. 

Threat Landscape

LightSpy poses a major threat to social media users as it allows threat actors extensive control over infected devices, including managing transmissions and disrupting device booting. Given its capabilities, LightSpy can be used for cyber espionage, targeting individuals, organisations, and potentially even governments. This underscores the challenges faced by users in both personal and business environments. 

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content