Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →ThreatFabric’s October 2024 analysis identified LightSpy iOS samples whose Core was labeled version 7.9.0. The samples had 28 plugins, up from 12 in an earlier documented version, and seven plugins with capabilities that could disrupt an iPhone’s operation or prevent it from booting. That is a finding about samples analyzed in 2024—not confirmation that 7.9.0 remains LightSpy’s latest version or that the malware is currently widespread.
What is the latest version of LightSpy iOS malware?
The latest version established by the sources available here is the one ThreatFabric analyzed in its report published October 29, 2024: an iOS Core labeled 7.9.0. Its prior documented comparison point was Core 6.0.0. The report does not establish whether a newer version appeared after its analysis, so 7.9.0 should not be described as the current latest release in 2026.
| Reported version | Plugin count | Destructive plugins | Supported iOS range |
|---|---|---|---|
| 6.0.0, previously documented by ThreatFabric | 12 | Not stated for this version in ThreatFabric’s comparison | Not stated in the cited comparison |
| 7.9.0, samples analyzed by ThreatFabric in 2024 | 28 | Seven plugins had destructive capabilities | Through iOS 13.3, according to ThreatFabric |
The 28-versus-12 comparison describes the plugin sets in the analyzed versions. It is not a count of infections or affected users. ThreatFabric’s technical analysis and a contemporaneous Infosecurity Magazine report discuss the expanded capabilities.
Can LightSpy brick an iPhone?
The analyzed 7.9.0 samples included plugins with destructive capabilities. ThreatFabric described actions that could freeze or otherwise destabilize a device and prevent it from booting. “Brick” is a useful shorthand for a device made unusable, but the report documents capabilities; it does not establish that every plugin ran, that every infected phone was permanently disabled, or that the seven destructive plugins all executed against victims.
#1 Best Overall
MITRE ATT&CK’s LightSpy entry also records destructive techniques, including disabling SpringBoard, changing the NVRAM auto-boot parameter, renaming the Wi-Fi daemon, deleting media or messenger-related files, and removing messaging applications. These are documented behaviors associated with the malware, not proof that every LightSpy sample performs every action. See MITRE ATT&CK’s LightSpy profile.
What can LightSpy do to an infected iPhone?
LightSpy is modular: its plugins can support different behaviors. Alongside destructive actions, MITRE’s profile describes collection and exfiltration capabilities. The exact activity depends on the components present and used; the number of plugins alone does not show what happened on a particular device.
Rank #2
- Disrupt operation: some analyzed plugins could interfere with stability, booting, or core device behavior.
- Damage or remove content and apps: documented techniques include deleting certain media or messenger-related files and removing messaging apps.
- Collect and send information: the malware’s mapped behaviors include gathering data and exfiltrating it.
These are capabilities documented across technical analyses, not a consumer diagnostic checklist. An iPhone freezing, failing to start, or behaving unusually does not by itself establish a LightSpy infection.
How did the analyzed samples infect devices?
ThreatFabric reported a historical exploit chain for samples supporting iOS through version 13.3. The report identified CVE-2020-9802, a Safari/WebKit exploit, for initial access and CVE-2020-3837 for privilege escalation. It also said the relevant remote-code-execution vulnerability had been patched in 2020.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteThis describes the chain reported for those samples; it is not evidence that a fully updated iPhone today is vulnerable to the same route. The supported range and exploit details should be read in the context of the analyzed software and the report’s publication date, not as a current warning about every iPhone.
Does the reporting show that LightSpy is widespread or active now?
No population-level infection estimate or prevalence statistic is established by the cited reporting. ThreatFabric examined five active command-and-control servers associated with the analyzed infrastructure. JSON files on those servers contained apparent deployment dates, with the latest observed date October 26, 2022. That date is an observation in server data reported in 2024; it does not prove ongoing deployment in 2026.
Rank #4
ThreatFabric raised the possibility that some infrastructure had been retained for demonstration, but did not establish that as the explanation. The report also said it found no evidence that LightSpy was promoted as malware-as-a-service on known attacker forums. Neither point demonstrates that the campaign is currently active or inactive.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should iPhone users do?
Apple says its mercenary-spyware threat notifications concern people individually targeted because of who they are or what they do. Apple describes these alerts as high-confidence and says the vast majority of users will never be targeted by such attacks. If Apple sends a threat notification, follow the instructions in the notification and consult Apple’s guidance on threat notifications and mercenary spyware. Do not treat ordinary device glitches as proof of spyware.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

