China-Linked Surveillance Platform Spans at Least 117 Servers, Targets Routers

LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections. At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in […]

Written By
LT
Liz Ticong
Aug 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections.

At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in 2020. 

Recent findings extend the threat into parts of the network many security teams may overlook.

Router implants can affect devices across the same network

Bestuzhev and Melikov confirmed two infected MikroTik routers, one in South Africa and another in the Czech Republic.

Once a router is compromised, LightSpy can change administrator credentials and DNS settings. Operators can redirect traffic through a proxy and retrieve Wi-Fi passwords stored on the device.

Control at the gateway can affect other devices using the same network. Altered DNS settings can steer connections elsewhere, and proxy controls can reroute traffic without requiring LightSpy to be installed on every connected phone or computer. 

Similar router compromises illustrate why gateway-level access can be difficult to catch with defenses centered on endpoints. 

One Beijing server exposed a much larger operation

The researchers said they started with a known command-and-control server in Beijing and used matching certificate characteristics to uncover related infrastructure. China accounted for 33 of the mapped servers, the largest share in any country.

The researchers said their investigation traced LightSpy’s development to a small private software company in Shenzhen, adding another connection between the platform and mainland China.

LightSpy appears to remain under active development. Recent code and newly registered infrastructure documented by the researchers extend into 2026, showing continued work on the spyware.

Demo access, billing controls and customer-specific configurations inside its operator panel indicate the platform can serve multiple customers. Bestuzhev and Melikov characterize LightSpy as a productized surveillance service rather than tooling created for a single operator.

Advertisement

Router compromise can escape endpoint-focused defenses

Security teams managing branch offices or remote workers could miss part of an intrusion if an investigation stops at laptops and phones. A clean endpoint does not rule out a compromised gateway, since endpoint detection and response primarily watches activity on the devices it monitors.

Unexplained DNS changes, altered proxy settings, or unfamiliar router scripts should put the gateway itself under scrutiny. Cleaning a laptop or replacing a phone may accomplish little if its traffic continues to pass through an infected router.

Bestuzhev and Melikov advise defenders to review scheduled scripts and inspect DNS and proxy settings on MikroTik devices. Keeping firmware current and using out-of-band monitoring can help expose unauthorized changes that normal endpoint controls may miss.

LightSpy adds another reason to include routers in incident response when suspicious activity continues after affected endpoints have been cleaned. Broader network security visibility can help determine whether an attacker’s remaining foothold is sitting at the gateway.

Read more: Barracuda’s Black Hat 2026 research shows how AI email assistants can give business email compromise attacks more speed and scale.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.