LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India
ID: 6bc66ffe-0b23-57f9-951f-e75d47eb9950
STIX ID: report--6bc66ffe-0b23-57f9-951f-e75d47eb9950
Feed Name: Arctic Wolf Blog
This report describes the resurgence of LightSpy (F_Warehouse), an advanced, modular iOS espionage implant targeting individuals in Southern Asia (likely political targets). It details the infection vector (compromised news sites), loader/core/plugin architecture, extensive spying capabilities (file exfiltration, audio recording, keychain access, camera, browser history, remote shell), command-and-control infrastructure (including IP 103.27.109.217 and operator panel), multiple IoCs (file hashes, URLs), and provides detection YARA rules and mitigation recommendations such as enabling Lockdown Mode and following mobile security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
