Two security reports on 6 August show different threats: phone-based credential theft at finance firms and LightSpy spyware activity across 13 countries.
Two reports published on 6 August describe different attack methods, but both point to current cyber risks rather than a distant trend. TechCrunch reported on Google researchers' findings that groups targeting large US financial and investment firms are calling employees' personal phones and posing as co-workers or IT staff to steal login details. In a separate report, TechCrunch also reported on Arctic Wolf's LightSpy research, which says the spyware has expanded beyond mainland China and is now targeting victims in more than a dozen countries, including the US.
What links the stories is not a single attacker or toolset, but a shared lesson: older social engineering tactics and increasingly capable surveillance malware can both still lead to serious security incidents.
How the phone-based attacks on finance firms work
According to the TechCrunch report citing Google researchers, the attackers call employees on personal mobile phones and pretend to be trusted internal contacts, such as co-workers or helpdesk staff. The aim is to get the target to enter their credentials and multi-factor authentication codes on spoofed websites. In plain English, that means the attacker tries to talk someone into logging into a fake page that captures the information needed to access real company systems.
This technique is known as voice phishing, or vishing. Here, the method is simple: the call creates trust, and the fake website collects the victim's username, password, and additional code. Google says the attackers then use that access to steal sensitive data and pressure victims with threats to publish it unless they pay.
Google named the groups Falcon, Helix, Pink, and Redact, but said they may all be part of a larger collective it tracks as UNC6671. The company also said it is unclear whether these are affiliates, splinter groups, or separate actors using the same Phishing-as-a-Service infrastructure. That uncertainty matters because the public group names seen by victims may not correspond neatly to one organisation or one shared operation.
The report says these attackers have also previously targeted companies in manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality. More recently, Google says they have targeted legal and financial organisations such as private equity firms. Reuters, as cited in the TechCrunch story, reported that victims include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG, though the companies either declined to comment or did not respond.
Google also said one cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year, and that the hackers usually demand from $750,000 to $3 million from victims. The source material does not say how firms are responding, but it does show that multi-factor authentication can still be undermined if employees are persuaded to hand over the codes designed to protect access.
What LightSpy is reported to do
In the second report, TechCrunch summarised Arctic Wolf's findings on LightSpy. The researchers said the spyware, first discovered in 2018 and previously linked to Chinese state-backed hackers, has evolved into what they describe as a commercial spyware platform operated by a single threat actor that caters to governments, enterprises, and militaries.
LightSpy is described as modular, meaning it can use different components for different jobs and devices. Arctic Wolf says it can target smartphones, Apple devices, Linux servers, and Windows PCs. The reported capabilities include stealing precise location data, chat messages, screen recordings, and stored passwords. The researchers also said the code is capable of remotely wiping and destroying data on a compromised device, which could leave that device unusable.
One notable change in the latest activity is that the spyware has also been found on routers. A router is the network device that connects devices in a home or office to each other and to the internet. If attackers compromise that system, Arctic Wolf says they can gain visibility and access to other devices on the same network. The report adds that some compromised routers are associated with NATO member countries.
Arctic Wolf said LightSpy has now targeted victims in 13 countries, including across Europe and the United States, and that the operation runs on a network of at least 117 servers in several countries. The researchers also said they linked the latest activity to a Chinese contractor after one of the spyware's operators used the LightSpy administrator panel to place a Kentucky Fried Chicken order using a real name and office address.
The report does not establish how widely LightSpy is being bought or deployed by customers. It says the platform features custom branding, billing, and demos for prospective customers, which suggests a commercial model, but the article does not identify named buyers. That leaves the scale of adoption open even as the technical capabilities appear broad.
Why these two reports matter together
The strongest conclusion supported by these reports is not that one new technique is taking over, but that attackers can still succeed through very different weak points. In Google's account, that weak point is employee trust during a phone call. In Arctic Wolf's account, it is the breadth of access a spyware platform can gain once a device or router is compromised.
What matters most is the overlap in consequence: both routes can expose sensitive data, and both leave important unanswered questions about scale, attribution, and who is behind the activity. Google says it is unclear how the extortion groups it tracks relate to each other operationally. Arctic Wolf attributes the latest LightSpy activity to a Chinese contractor, but the report as summarised by TechCrunch does not identify customers for the spyware platform.
For organisations, a likely implication is that people, endpoints, and network equipment cannot be treated as separate security problems. The Google report points to risks around staff using personal phones and being asked to enter credentials into fake sites. The LightSpy report points to the possibility that a compromised router could expose multiple devices on the same network. The sources do not describe a single standard business response, but they do support a more basic conclusion: very different attack paths can still lead to the same result, which is loss of sensitive information and leverage for extortion or surveillance.