HomeSecurityLightSpy spyware targets iOS users

LightSpy spyware targets iOS users

Cybersecurity researchers have discovered a new espionage campaign targeting iOS users in South Asia, aiming to deliver a spyware called LightSpy.

LightSpy spyware

“ The latest version of LightSpy, called “F_Warehouse,” features a modular framework with extensive espionage capabilities ,” BlackBerry ’s Threat Research and Intelligence Team said .

According to VirusTotal, the attackers may have also targeted users in India.

See also: 'eXotic Visit' spyware targets Android users in India and Pakistan

The LightSpy spyware was first observed in 2020 by Trend Micro and Kaspersky as an iOS backdoor distributed via watering hole attacks via compromised news sites. Subsequent analysis by ThreatFabric in October 2023 revealed that the infrastructure and functionality resembled the Android malware DragonEgg, which is attributed to the Chinese group APT41 (also known as Winnti).

At this time, we do not know how the initial intrusion for the LightSpy infection occurs, although it is believed to be through compromised news websites.

Initially, there is a first-stage loader that acts as a launchpad for the main LightSpy backdoor and its various add-ons. These are retrieved from a remote server for data collection .

The LightSpy spyware is both fully-featured and modular, allowing its operators to collect sensitive information, such as contacts, messages , location data, and audio recordings during VoIP calls.

The latest version discovered by BlackBerry further expands its capabilities to steal files and data from popular apps like Telegram, QQ, and WeChat, iCloud Keychain data, and browser history.

See also: Apple: Warns iPhone users about spyware attacks

Additionally, there is networks Wi-Fi and details about installed applications, the ability to take photos via the device's camera, record audio, and execute shell commands received from the server.

“The LightSpy spyware uses certificate pinning to prevent detection and interception of communication with the command and control (C2) server,” Blackberry said. “So, if the victim is on a network where traffic is being analyzed, no connection to the C2 server will be established.”

Further investigation has shown the involvement of Chinese speakers . In addition, the LightSpy spyware communicates with a server located at 103.27[.]109[.]217, which also hosts an administrator panel with an error message in Chinese when entering incorrect login credentials.

“The malware’s expanded capabilities, including extensive data theft, audio surveillance, and potential complete device, pose a serious risk to targeted individuals and organizations in South Asia,” BlackBerry said.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: US: Sanctions on Predator spyware operators

LightSpy spyware targets iOS users

How can someone protect their digital life from spyware?

One of the most effective ways to protect yourself is to use reliable security. These programs scan your device for spyware and remove it (e.g. LightSpy). They also offer real-time protection, alerting you when an application tries to install spyware on your computer.

It's also important to keep your operating system and all programs up to date. These updates often include security fixes that can help protect your computer from spyware.

Another important tip is to be careful with the emails and messages you receive. This software is often spread through phishing, where attackers try to convince you to click on a malicious link or open a dangerous attachment.

Finally, it's important to keep backups of your important files. While this won't directly protect you from spyware, it will help you recover your data if your computer is infected.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS