The LightSpy advanced persistent threat (APT) group has significantly upgraded its surveillance capabilities with a 100+ command framework targeting Android, iOS, Windows, macOS, and Linux systems, according to new infrastructure analysis.
This modular malware now employs refined data exfiltration techniques against social media platforms and expanded device control mechanisms, marking a strategic shift toward omnidirectional cyberespionage.
According to Hunt.io Report, Threat Hunting Platform, the latest command-and-control (C2) server at 149.104.18[.]80:10000 reveals a 182% increase in supported operations compared to the previously documented 45.125.34[.]126:49000 server, which hosted 55 commands.
The updated cmd_list endpoint (/ujmfanncy76211/front_api) introduces granular control mechanisms like 传输控制 (“transmission control”) and 上传插件版本详细信息 (“upload plugin version details”), enabling operators to manage compromised devices through version-aware plugin deployments.
Notably, the framework now targets Facebook and Instagram database files through dedicated Android commands:
This represents LightSpy’s first known integration of social media database extraction, potentially exposing private messages, contact lists, and authentication tokens stored in SQLite databases.
Analysis of the 149.104.18[.]80 server’s port 40002 endpoint uncovered 15 Windows-specific DLL plugins designed for x86/x64 architectures. These components exhibit surveillance capabilities through:
The plugins follow a development pattern evidenced by PDB paths like W:\yk\Bigfoot\bin*.pdb, suggesting compartmentalized project structures.
Version numbering (0.0.0.0-0.0.0.2) indicates active development cycles, with “Terminal” plugins likely hooking into Windows Console API for command execution monitoring.
LightSpy’s infrastructure employs multi-port C2 channels across:
The framework’s Vue.js-based admin interface (Console v3.5.0) was briefly exposed through a misconfigured /third_login/:username endpoint, revealing device grouping capabilities and real-time terminal log access.
Forensic artifacts from the 2021-12-31 core version (MD5:81d2bd4781e3753b508ff6d966dbf160) show improved session persistence mechanisms compared to the 2020-12-21 build.
Organizations should implement:
Network defenders can detect LightSpy’s TLS fingerprint (JA3:6734f37431670b3ab4292b8f60f29984) and monitor for anomalous requests to /963852741/ios/version.json endpoints.
The framework’s expanded command set enables threat actors to:
This development positions LightSpy as a polymorphic threat capable of bridging OS-specific vulnerabilities into cross-platform intrusion campaigns.
Given their role in plugin distribution and C2 operations, continued monitoring of Cloudie Limited-hosted IPs (103.238.227[.]138, 43.248.8[.]108) is critical.
Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response and Threat Hunting – Register Here
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…