LightSpy

MITRE ATT&CK: S1185 View on attack.mitre.org

Aliases: LightSpy

First seen
2018-01-01 00:00:00
Malware type
spyware, credential-stealer, downloader
Family
Malware family
Operating systems
android, windows, ios, macos
Related IoCs
28 (16 malicious)
Last IoC activity
2026-08-11 11:47:38
Profile updated
2026-07-07 13:08:03

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment

Targeted regions: country_code:hk country_code:sg

Context

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.

Recent IoC activity

16 malicious indicators in Maltiverse are attributed to LightSpy (S1185). The 16 most recently updated:

Detection coverage

  • 2 YARA rules
  • 209 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Keychain (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Screen Capture (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Shared Modules (attack-pattern)
  • Audio Capture (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Binary Padding (attack-pattern)
  • Software Discovery (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Contact List (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Keychain (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Archive Collected Data (attack-pattern)

Used by threat actors

Detection rules

  • VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_Core (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Lightspy_Orchestrator_Decoded_C2_Strings (yara-rule)

Reports & references

  • Kaspersky — 96407 (report)
  • volexity.com — Brazenbamboo Weaponizes Forticlient Vulnerability To Steal Vpn Credentials Via Deepdata (report)
  • Trend Micro — Operation Poisoned News Hong Kong Users Targeted With Mobile Malware Via Local News Links (report)
  • Trend Micro — Tech Brief Operation Poisoned News Hong Kong Users Targeted With Mobile Malware Via Local News Links (report)
  • threatfabric.com — Lightspy Mapt Mobile Payment System Attack (report)
  • malpedia.caad.fkie.fraunhofer.de — Ios.Lightspy (report)
  • hunt.io — Lightspy Malware Targets Facebook Instagram (report)
  • hunt.io — Tracking Lightspy Certificates As Windows Into Adversary Behavior (report)
  • MITRE ATT&CK — S1185 (report)
  • blogs.blackberry.com — Lightspy Returns Renewed Espionage Campaign Targets Southern Asia Possibly India (report)

External references