TF-MAL-ios.lightspy
📛 Threat Title
Malware family: lightSpy
Description
ThreatFox malware family `ios.lightspy`. Printable name: lightSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ios.lightspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.lightspy
IOC database
- Type
- domain
- Value
ios.lightspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ios.lightspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.lightspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The malware has been deployed in targeted attacks via watering hole techniques and exploits, adapting its infrastructure to evade detection. Recent analysis highlights LightSpy's focus on extracting Facebook and Instagram database files, marking a shift from its traditional emphasis on messaging applications like Telegram and WeChat.
-
web:arcticwolf.com
The threat actor behind LightSpy has expanded their toolset with the introduction of DeepData, a modular Windows-based surveillance framework that significantly broadens their espionage capabilities.
-
web:attack.mitre.org
LightSpy First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms.
-
web:cybersecuritynews.com
LightSpy iOS Malware Upgraded In May 2024, cybersecurity firm ThreatFabric uncovered significant developments in the LightSpy malware ecosystem that unveiled a "unified server infrastructure" that directed both "macOS" and "iOS" campaigns.
-
web:hunt.io
LightSpy exploits mobile devices for surveillance, targeting activists and high-profile individuals. Explore its features and risks.
-
web:thehackernews.com
LightSpy malware now supports 100+ commands across platforms, targeting Facebook and Instagram data while expanding operational control.
-
web:www.mphasis.com
LightSpy's control panel by exploiting a misconfiguration that allowed unauthorized access to the authenticated interface, gaining insights into the functionality, infrastructure, and infected devices. The Android version of this malware on the same C2 as the macOS version, it doesn't appear the iOS version is also present.
-
web:www.securemac.com
LightSpy is a hybrid threat that compromises a macOS-enabled Intel (or Apple Silicon with Rosetta 2 enabled) device. This malware has the capabilities to be upgraded over time and include features such as spying on the user and stealing information from the user.
-
web:www.thousandguards.com
The LightSpy infection chain typically follows these key steps attackers deliver the malware through targeted infections, using exploits to compromise devices silently. The malware extracts sensitive data from social media apps, keychain credentials, call logs, and browsing history.
-
web:www.threatfabric.com
ThreatFabric's latest insights on LightSpy malware , targeting both iOS and macOS. Learn about the evolving tactics, new destructive features, and the importance of keeping devices updated to defend against these advanced cyber threats.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.