China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

与中国有关的 LightSpy 间谍软件被发现针对包括美国在内的 13 个国家的受害者

Security researchers say they have evidence that a Chinese-linked spyware has expanded from mainland China to now target victims in over a dozen countries, including across Europe and the United States. The previously identified spyware also has new functionality capable of stealing troves of data and remotely bricking devices. 安全研究人员表示,他们有证据表明,一种与中国有关的间谍软件已从中国大陆扩展,目前正针对包括欧洲和美国在内的十多个国家的受害者。这种此前已被识别的间谍软件还具备了窃取海量数据和远程“变砖”(使设备无法使用)的新功能。

The researchers at cybersecurity firm Arctic Wolf said that the LightSpy spyware, first discovered in 2018 and previously linked to Chinese state-backed hackers, has since evolved into a commercial spyware platform operated by a single threat actor who caters to governments, enterprises, and militaries. The platform is said to feature custom branding, billing, and demos for advertising it to prospective customers. The findings underscore how the use of spyware continues to proliferate beyond governments and nation-backed hackers, and more broadly into the private industry. 网络安全公司 Arctic Wolf 的研究人员表示,LightSpy 间谍软件最早于 2018 年被发现,此前曾与中国国家支持的黑客有关联。如今,它已演变成一个商业间谍软件平台,由单一威胁行为者运营,专门服务于政府、企业和军队。据称,该平台具备定制品牌、计费系统和演示功能,用于向潜在客户进行推广。这些发现凸显了间谍软件的使用如何持续扩散,不仅限于政府和国家支持的黑客,更广泛地渗透到了私营行业。

LightSpy is a modular spyware platform that allows whoever is controlling it to attack a multitude of different devices, including smartphones, Apple devices, Linux servers, and Windows PCs. By using exploits for each device, the spyware can steal large amounts of sensitive information from its targets, including precise location data, chat messages, screen recordings, and stored passwords. The researchers also said the code is capable of remotely wiping and destroying data on a compromised device. LightSpy 是一个模块化间谍软件平台,允许控制者攻击多种不同设备,包括智能手机、苹果设备、Linux 服务器和 Windows PC。通过利用针对每种设备的漏洞,该间谍软件可以从目标设备中窃取大量敏感信息,包括精确的地理位置数据、聊天记录、屏幕录像和存储的密码。研究人员还指出,该代码具备远程擦除和销毁受感染设备上数据的能力。

The researchers said that LightSpy has now been identified infecting routers, which researchers say they had not seen before. By attacking routers, the hackers can gain visibility and access to any other device on the same network. Some of the compromised routers are associated with NATO member countries, said Arctic Wolf. According to the company, LightSpy operates a network of at least 117 servers in several countries around the world. 研究人员表示,目前已发现 LightSpy 开始感染路由器,这是研究人员此前从未见过的。通过攻击路由器,黑客可以获得对同一网络下任何其他设备的可见性和访问权限。Arctic Wolf 表示,部分受感染的路由器与北约成员国有关。据该公司称,LightSpy 在全球多个国家运营着至少 117 台服务器组成的网络。

The researchers said they were able to link the latest activity to a Chinese contractor after one of the spyware’s operators used the LightSpy administrator’s panel to place an order with Kentucky Fried Chicken using his real name and office address. 研究人员表示,他们之所以能将最新的活动与一名中国承包商联系起来,是因为该间谍软件的一名操作员在使用 LightSpy 管理员面板时,用自己的真实姓名和办公地址在肯德基(KFC)下了订单。