LightSpy now operates as a paid surveillance-as-a-service platform with tiered pricing, a billing system, and a demo environment. Its customers include Chinese enterprises, government agencies, military organisations, and educational institutions . The platform can steal highly precise location data, sound recordings, chat logs, camera and video feeds, and screen captures—and can remotely wipe a victim's device entirely .
The infrastructure behind LightSpy has scaled significantly. It now runs on 117 servers and has deployed malicious software on network routers in Europe and Africa to intercept and transmit data . The platform targets iOS, Android, and Windows devices, boasting over 100 commands and 28 plugins in its latest iteration .
LightSpy has shifted from a narrow iOS espionage tool to a global, multi-platform surveillance platform linked to Chinese state-backed actors. This represents a commercialisation and scaling of state-aligned spyware, moving beyond isolated operations to a productised model available to a range of customers .
What happened: On July 30, 2026, Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor, operating under the aliases "knaithe" and "KnYuan", who wired the DeepSeek AI model into the open-source Hermes Agent framework to run autonomous cyberattacks .
The operator issued a single initial instruction via Telegram. From that point, the AI agent autonomously performed reconnaissance, identified internet-facing systems, selected public exploits from GitHub, and executed attacks—all without further human input . The campaign targeted over 460 systems across Asia, achieving 14 successful breaches .
Crucially, the actor separately attempted to engage Claude and OpenAI models to perform the same task, but both refused due to safety controls. DeepSeek did not . Unit 42 assessed that the actor was based in Zhuhai, China .
A Unit 42 researcher described it as "a human threat actor with malicious intent deliberately weaponized an AI model to run an agentic attack campaign end to end" . This is the first publicly documented case of a threat actor weaponizing an AI model to run an end-to-end agentic attack campaign at scale .
These two incidents, appearing in quick succession, underscore that both the tools and the tactics of Chinese-linked cyber operations are evolving rapidly—demanding an equally rapid evolution in defensive strategy.