LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections.
At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in 2020.
Recent findings extend the threat into parts of the network many security teams may overlook.
Router implants can affect devices across the same network
Bestuzhev and Melikov confirmed two infected MikroTik routers, one in South Africa and another in the Czech Republic.
Once a router is compromised, LightSpy can change administrator credentials and DNS settings. Operators can redirect traffic through a proxy and retrieve Wi-Fi passwords stored on the device.
Control at the gateway can affect other devices using the same network. Altered DNS settings can steer connections elsewhere, and proxy controls can reroute traffic without requiring LightSpy to be installed on every connected phone or computer.
Similar router compromises illustrate why gateway-level access can be difficult to catch with defenses centered on endpoints.
One Beijing server exposed a much larger operation
The researchers said they started with a known command-and-control server in Beijing and used matching certificate characteristics to uncover related infrastructure. China accounted for 33 of the mapped servers, the largest share in any country.
The researchers said their investigation traced LightSpy’s development to a small private software company in Shenzhen, adding another connection between the platform and mainland China.
LightSpy appears to remain under active development. Recent code and newly registered infrastructure documented by the researchers extend into 2026, showing continued work on the spyware.
Demo access, billing controls and customer-specific configurations inside its operator panel indicate the platform can serve multiple customers. Bestuzhev and Melikov characterize LightSpy as a productized surveillance service rather than tooling created for a single operator.
Router compromise can escape endpoint-focused defenses
Security teams managing branch offices or remote workers could miss part of an intrusion if an investigation stops at laptops and phones. A clean endpoint does not rule out a compromised gateway, since endpoint detection and response primarily watches activity on the devices it monitors.
Unexplained DNS changes, altered proxy settings, or unfamiliar router scripts should put the gateway itself under scrutiny. Cleaning a laptop or replacing a phone may accomplish little if its traffic continues to pass through an infected router.
Bestuzhev and Melikov advise defenders to review scheduled scripts and inspect DNS and proxy settings on MikroTik devices. Keeping firmware current and using out-of-band monitoring can help expose unauthorized changes that normal endpoint controls may miss.
LightSpy adds another reason to include routers in incident response when suspicious activity continues after affected endpoints have been cleaned. Broader network security visibility can help determine whether an attacker’s remaining foothold is sitting at the gateway.
Read more: Barracuda’s Black Hat 2026 research shows how AI email assistants can give business email compromise attacks more speed and scale.





