Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1185
MITRE ATT&CK Malware

LightSpy (S1185)

ShareXLinkedInRedditHN

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.(Citation: MelikovBlackBerry LightSpy 2024)

Platforms: Android, Windows, iOS, macOS

▪Techniques implemented (51)

T1057Process DiscoveryT1480Execution GuardrailsT1555.001KeychainT1105Ingress Tool TransferT1113Screen CaptureT1041Exfiltration Over C2 ChannelT1071.001Web ProtocolsT1129Shared ModulesT1123Audio CaptureT1027.013Encrypted/Encoded FileT1082System Information DiscoveryT1083File and Directory DiscoveryT1217Browser Information DiscoveryT1027.001Binary PaddingT1518Software DiscoveryT1046Network Service DiscoveryT1437.001Web ProtocolsT1544Ingress Tool TransferT1422.002Wi-Fi DiscoveryT1636.003Contact ListT1623Command and Scripting InterpreterT1634.001KeychainT1658Exploitation for Client ExecutionT1406Obfuscated Files or InformationT1532Archive Collected DataT1424Process DiscoveryT1636.002Call LogT1409Stored Application DataT1646Exfiltration Over C2 ChannelT1456Drive-By CompromiseT1422System Network Configuration DiscoveryT1509Non-Standard PortT1429Audio CaptureT1660PhishingT1421System Network Connections DiscoveryT1642Endpoint Denial of ServiceT1631Process InjectionT1533Data from Local SystemT1423Network Service ScanningT1430Location TrackingT1513Screen CaptureT1512Video CaptureT1426System Information DiscoveryT1404Exploitation for Privilege EscalationT1582SMS ControlT1418Software DiscoveryT1636.004SMS MessagesT1575Native APIT1655MasqueradingT1662Data DestructionT1398Boot or Logon Initialization Scripts

▪Used by groups (1)

G0096APT41
S1185on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.