LightSpy is a modular spyware and backdoor platform primarily associated with Chinese-linked surveillance activity. It was first publicly identified in mobile espionage operations targeting iPhone users through watering-hole attacks that used malicious pages masquerading as local news or forum content and exploited iOS vulnerabilities to install the implant. Subsequent reporting indicates the platform expanded beyond its original focus on mainland China to victims in multiple countries, and evolved into a broader commercial spyware offering reportedly marketed to government, enterprise, and military customers.
On iOS, LightSpy has been documented as a feature-rich implant capable of remote shell command execution, file management, device profiling, and extensive surveillance. Its modules have collected contacts, SMS messages, call history, location data, Keychain material, Wi-Fi history and nearby network information, installed application data, running process information, browser history, and content from messaging applications including Telegram, QQ, WeChat, and WhatsApp. It communicates with command-and-control infrastructure over HTTPS and WebSockets and exfiltrates collected data in structured form. LightSpy also includes reconnaissance functionality such as local subnet and nearby Wi-Fi scanning.
Later variants show substantial growth in modularity and capability, including macOS-linked development overlap and newer iOS builds with many additional plugins. Reported functions in these newer versions include audio and camera-related collection, simulated push-message or alert functionality, and destructive modules capable of freezing devices, interfering with boot, or remotely wiping or destroying data. Reporting also attributes LightSpy with targeting a wider set of systems beyond iPhones, including macOS, Windows, Linux, and routers, using device-specific exploits. Router compromise has been assessed as especially valuable because it can provide visibility into and access to other devices on the same network.
LightSpy is best characterized as a spyware platform with backdoor functionality: it supports persistent post-compromise access, remote tasking, surveillance, data theft, and in some variants destructive actions. It has been linked in open reporting to Chinese state-backed or Chinese contractor-associated activity, though some later assessments describe it as a commercially operated platform rather than a tool used exclusively in a single state campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The full exploit chain involves exploiting a silently patched Safari bug on multiple recent iOS versions and a customized kernel exploit. Once the Safari browser renders the exploit, a silently patched bug is taken advantage of, which leads to the exploitation of a known kernel vulnerability to gain root privileges. The exploited kernel bug has been assigned with the CVE ID CVE-2019-8605. | The iOS malware, which we named "lightSpy" (detected by Trend Micro as IOS_LightSpy.A), is a modular backdoor that allowed the attacker to remotely execute a shell command and manipulate files on the infected device.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access... This time it was CVE-2020-9802, which was fixed in iOS 13.5 | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
They utilized the publicly available Safari exploit CVE-2020-9802 for initial access and CVE-2020-3837 for privilege escalation... The threat actor created "20012001330.png" to trigger vulnerability CVE-2020-3837 using a “time_waste” exploit and a corresponding jailbreak kit. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
This time it was CVE-2020-9802, which was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6. | In May 2024, ThreatFabric published a report about LightSpy for macOS. During that investigation, we discovered that the threat actor was using the same server for both macOS and iOS campaigns. Thanks to this, we were also able to obtain the most recent samples of LightSpy for iOS.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2020, a watering hole was discovered that utilized a full remote iOS exploit chain to deploy a feature-rich implant named LightSpy.
“The technical details around the functionality of the iOS implant, called LightSpy… reveal a low-to-mid capable actor. However, the iOS implant is a modular and exhaustively functional iOS surveillance framework.”
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Users with unpatched iPhones that access the concerned links will be infected with an iOS malware that can spy on and take full control of the devices. | Trend Micro discovered a watering hole attack against iOS users in Hong Kong... The campaign designed several webpages disguised as local news pages then injected them with an iframe that loads an iOS exploit.
After downloading all the payloads, the exploit spawns a daemon using launchctl with “ircbin.plist” as the argument.
The iOS malware, which we named "lightSpy"... allowed the attacker to remotely execute a shell command...
This daemon uses irc_loader as an executable. This loader is just a launcher and will be used to start up the main malicious agent deployed on the target side.
After downloading all the payloads, the exploit spawns a daemon using launchctl with “ircbin.plist” as the argument.
Once the Safari browser renders the exploit, a silently patched bug is taken advantage of, which leads to the exploitation of a known kernel vulnerability to gain root privileges. The exploited kernel bug has been assigned with the CVE ID CVE-2019-8605.
The startup parameters are hidden in the irc_loader binary and are encrypted with the AES algorithm.
It first gets the plug-in name, path, and classname, then uses the path to load the plug-in file through the dlopen() function. After that, it uses the objc_getClass() function to get the exposed class object...
The campaign also employs modules specifically designed to exfiltrate data from popular messenger applications such as QQ, WeChat, and Telegram.
The malware also reports the surrounding environment of the device by: Scanning local network IP address; Scanning available Wi-Fi network.
Command 16002 is used to get the process list... it first calls the “ps -Aef” command to get the process list...
This module is mainly for gathering and uploading information such as iPhone hardware information...
This module is mainly used for file or directory operation, including the following sub-commands: get directory and file list... and get the directories of applications.
After that, it initializes a thread using the libwebsockets library to implement the messages' receiving function.
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular commercial spyware platform linked to Chinese state-backed activity that infects smartphones, Apple devices, Linux servers, Windows PCs, and routers via device-specific exploits. It steals sensitive data including location, chat messages, screen recordings, and passwords, can remotely wipe devices, and router infections provide visibility and access across compromised networks.
A modular spyware platform capable of targeting smartphones, Apple devices, Linux servers, Windows PCs, and routers. It uses device-specific exploits to steal sensitive data such as location data, chat messages, screen recordings, and stored passwords, and can also remotely wipe or destroy data on compromised devices.
Modular spyware implant with expanded command set; targets multiple OSes and harvests data including from social media platforms.
Cross-platform surveillance framework affecting macOS and other OSes, enabling surveillance and data exfiltration; described as often linked to Chinese APT groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.