s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ios.lightspy

📛 Threat Title

Malware family: lightSpy

Category: lightSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ios.lightspy`. Printable name: lightSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ios.lightspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.lightspy

IOC database

Type
domain
Value
ios.lightspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ios.lightspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.lightspy

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The malware has been deployed in targeted attacks via watering hole techniques and exploits, adapting its infrastructure to evade detection. Recent analysis highlights LightSpy's focus on extracting Facebook and Instagram database files, marking a shift from its traditional emphasis on messaging applications like Telegram and WeChat.

  • web:arcticwolf.com

    The threat actor behind LightSpy has expanded their toolset with the introduction of DeepData, a modular Windows-based surveillance framework that significantly broadens their espionage capabilities.

  • web:attack.mitre.org

    LightSpy First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms.

  • web:cybersecuritynews.com

    LightSpy iOS Malware Upgraded In May 2024, cybersecurity firm ThreatFabric uncovered significant developments in the LightSpy malware ecosystem that unveiled a "unified server infrastructure" that directed both "macOS" and "iOS" campaigns.

  • web:hunt.io

    LightSpy exploits mobile devices for surveillance, targeting activists and high-profile individuals. Explore its features and risks.

  • web:thehackernews.com

    LightSpy malware now supports 100+ commands across platforms, targeting Facebook and Instagram data while expanding operational control.

  • web:www.mphasis.com

    LightSpy's control panel by exploiting a misconfiguration that allowed unauthorized access to the authenticated interface, gaining insights into the functionality, infrastructure, and infected devices. The Android version of this malware on the same C2 as the macOS version, it doesn't appear the iOS version is also present.

  • web:www.securemac.com

    LightSpy is a hybrid threat that compromises a macOS-enabled Intel (or Apple Silicon with Rosetta 2 enabled) device. This malware has the capabilities to be upgraded over time and include features such as spying on the user and stealing information from the user.

  • web:www.thousandguards.com

    The LightSpy infection chain typically follows these key steps attackers deliver the malware through targeted infections, using exploits to compromise devices silently. The malware extracts sensitive data from social media apps, keychain credentials, call logs, and browsing history.

  • web:www.threatfabric.com

    ThreatFabric's latest insights on LightSpy malware , targeting both iOS and macOS. Learn about the evolving tactics, new destructive features, and the importance of keeping devices updated to defend against these advanced cyber threats.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.