LightSpy
MITRE ATT&CK: S1185 View on attack.mitre.org
Aliases: LightSpy
- First seen
- 2018-01-01 00:00:00
- Malware type
- spyware, credential-stealer, downloader
- Family
- Malware family
- Operating systems
- android, windows, ios, macos
- Related IoCs
- 28 (16 malicious)
- Last IoC activity
- 2026-08-11 11:47:38
- Profile updated
- 2026-07-07 13:08:03
Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment
Targeted regions: country_code:hk country_code:sg
Context
First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.
Recent IoC activity
16 malicious indicators in Maltiverse are attributed to LightSpy (S1185). The 16 most recently updated:
Detection coverage
- 2 YARA rules
- 209 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Execution Guardrails (attack-pattern)
- Keychain (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Screen Capture (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Web Protocols (attack-pattern)
- Shared Modules (attack-pattern)
- Audio Capture (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Information Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Binary Padding (attack-pattern)
- Software Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- Contact List (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Keychain (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Archive Collected Data (attack-pattern)
Used by threat actors
- APT41 (threat-actor)
Detection rules
- VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_Core (yara-rule)
- VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_C2_Strings (yara-rule)
Reports & references
- Kaspersky — 96407 (report)
- volexity.com — Brazenbamboo Weaponizes Forticlient Vulnerability To Steal Vpn Credentials Via Deepdata (report)
- Trend Micro — Operation Poisoned News Hong Kong Users Targeted With Mobile Malware Via Local News Links (report)
- Trend Micro — Tech Brief Operation Poisoned News Hong Kong Users Targeted With Mobile Malware Via Local News Links (report)
- threatfabric.com — Lightspy Mapt Mobile Payment System Attack (report)
- malpedia.caad.fkie.fraunhofer.de — Ios.Lightspy (report)
- hunt.io — Lightspy Malware Targets Facebook Instagram (report)
- hunt.io — Tracking Lightspy Certificates As Windows Into Adversary Behavior (report)
- MITRE ATT&CK — S1185 (report)
- blogs.blackberry.com — Lightspy Returns Renewed Espionage Campaign Targets Southern Asia Possibly India (report)