Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users
ID: 237d750a-e808-5286-bf6f-ae7e71dd22f1
STIX ID: report--237d750a-e808-5286-bf6f-ae7e71dd22f1
Feed Name: The Hacker News
Cybersecurity firms have identified a renewed LightSpy iOS espionage campaign (dubbed 'F_Warehouse') targeting users in South Asia, likely delivered via compromised news websites. The modular implant harvests contacts, SMS, precise location, call audio, files, app data (Telegram, QQ, WeChat), iCloud Keychain, and browser history, uses certificate pinning, and contacts a C2 at 103.27.109.217; code and infrastructure artifacts suggest possible Chinese-state links and overlap with APT41-related tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
