Once concentrated in mainland China, LightSpy now operates across more than a dozen countries, including the United States and multiple European nations—some of which are NATO members . Arctic Wolf identified at least 117 command-and-control (C2) servers worldwide supporting the operation
.
Beyond theft, LightSpy includes a destructive capability: it can remotely wipe a target's device, effectively bricking it .
The most striking detail in the report is how researchers traced the current operation to a specific Chinese contractor company. While using the LightSpy administrator panel, one of the platform's operators accidentally placed a KFC (Kentucky Fried Chicken) delivery order using his real name and office address . This operational security error provided Arctic Wolf with the breadcrumbs needed to link the infrastructure directly to its operator
.
Arctic Wolf is now consulting with the U.S. Department of Homeland Security and plans to share its findings with law enforcement .