What happened
Cybersecurity researchers at Arctic Wolf published new findings on LightSpy, a spyware platform first spotted in 2018 that has quietly grown from state-linked malware into what the firm now describes as a commercial surveillance-for-hire operation run by a single group and sold to governments, enterprises and militaries. The latest campaign, active in more than 13 countries across Europe and the United States, including several NATO members, marks a notable expansion in what LightSpy can infect: beyond smartphones, Apple devices, Windows PCs and Linux servers, the platform now compromises routers directly, giving attackers a foothold across an entire office or home network rather than just one device. Once installed, LightSpy can pull location data, chat messages and passwords, capture screen recordings, and remotely wipe data from infected devices. Researchers found the operation running at least 117 command-and-control servers worldwide. Investigators traced the operators to a Chinese contractor after one of them reportedly used the spyware's own admin panel to place a food order under his real name and office address.
Why it matters for your business
The shift to compromising routers is the detail worth paying attention to. Most small businesses treat their router as a set-and-forget box in a closet, rarely updated after installation. LightSpy's growth shows why that's a risk: a single compromised router can expose every device on the network behind it, from point-of-sale systems to employee laptops, without anyone installing anything themselves. And while LightSpy's confirmed targets so far skew toward government and enterprise espionage, the existence of a commercial spyware-for-hire market means similar capability is increasingly available to whoever is willing to pay for it, not just nation-states.
What to do
Check when your office router last received a firmware update, and if it's end-of-life hardware from a vendor that no longer patches it, plan to replace it. Segment guest and IoT devices onto a separate network from the one handling payments or sensitive files, so a single compromised device doesn't expose everything else on your network.
