LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India

Quite interesting may not be something for the majority of us to worry about, but seeing as it’s using watering hole attacks might be best to be mindful of this.

What is LightSpy?

LightSpy is a sophisticated iOS implant, first reported in 2020 in connection with a watering-hole attack against Apple device users. Specifically, it is a fully-featured modular surveillance toolset that primarily focuses on exfiltrating victims’ private information, including hyper-specific location data and sound recording during voice over IP (VOIP) calls. This makes it particularly dangerous to victims, with as many consequences as can be imagined relating to a threat actor being able to locate their target with near-perfect accuracy.

This report details the resurgence of the LightSpy mobile espionage campaign, which focuses on targets in Southern Asia and probably India, potentially indicating a renewed focus on political targets and tensions in the region.

Beyond our findings, the echoes of concern reach further. VirusTotal submissions from India suggest potential victims within its borders, aligning with recent warnings by Apple on detections within the same country.

The return of LightSpy, now equipped with the versatile “F_Warehouse” framework, signals an escalation in mobile espionage threats. The expanded capabilities of the malware, including extensive data exfiltration, audio surveillance, and potential full device control, pose a severe risk to targeted individuals and organizations in Southern Asia.

Does LightSpy still target iOS/Apple devices alone, or is Android also vulnerable?

As far as I could tell from the report it’s seems to be iOS only.
However I’ve seen this:

I won’t pretend that I fully understand this but it seems that DragonEgg does have some of Lightspys core in it?
So it seems the code(?) of Lightspy can be flexible enough to be implemented into other Malware to target other ecosystems?

2 Likes

The decision to use malware targeting iOS is interesting seeing how the vast majority of India is on android/AOSP based OS.

2 Likes

Perhaps they already have sufficient methods of espionage for those devices? In India Apple is seen as a more luxury smartphone so perhaps this is also to target higher profile individuals.

3 Likes

To be honest that was my first thought that the target might be higher profile people. Seeing as it’s secretly recording people and stealing files and documents from them, which I can imagine is for blackmail purposes.

3 Likes

Interesting…some of my peers are in Asia so I believe this information will be useful in helping them stay safer online. Thanks a lot @anon82669666

2 Likes

@anon70356902 You’re welcome :blush::+1:t2:

2 Likes