CSIDB logo
Threat actor

L.M.

Attribution profile

Type
Activist
Location
China
Known incidents
1 incident
Sources
0 sources
First seen
2018-02-01
Last seen
2018-02-01
Updated
2026-08-01 20:17
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the initials L.M. has been identified in open‑source reporting as the individual responsible for a 2018 intrusion into the servers of TheTruthSpy, a consumer spyware vendor. The actor operates solely under that alias and has not been linked to any additional names or handles in the disclosed sources. Public attributions place L.M.’s location in China, based on the contextual information supplied with the threat actor profile. The actor first emerged when they contacted a journalist in February 2018 to disclose the compromise and provide evidence of the breach. No further aliases, affiliations, or organizational ties have been revealed in the available material.

L.M.’s activity has been directed at firms that market stalkerware or consumer spyware applications designed for monitoring personal devices. In interviews the actor explicitly stated that the stolen data could be used to ransomware victims and generate dirty money, indicating a financially oriented objective as expressed by the actor themselves. Technical details show that L.M. reverse‑engineered TheTruthSpy’s Android application to uncover a server‑side vulnerability that allowed administrative access. After identifying the flaw, the actor crafted web requests that returned user credentials stored in plaintext, which were then harvested en masse through an automated script. The intrusion also granted access to media files containing unique device identifiers linked to each victim’s phone, enabling correlation of surveillance data with specific accounts.

The most notable operation attributed to L.M. is the February 2018 breach of TheTruthSpy, which exposed more than ten thousand customer accounts including login credentials, intercepted communications, location information, pictures and audio recordings. During that incident the actor demonstrated how weak security practices—such as plaintext credential storage—could be exploited to obtain full administrative control over the provider’s backend infrastructure. The breach highlighted the broader risks within the stalkerware industry, where multiple similar providers have suffered comparable compromises. L.M. reported losing access after TheTruthSpy updated its servers, suggesting the intrusion was temporary and dependent on the existing vulnerability. This case remains one of the few publicly documented examples of an individual targeting the consumer spyware sector for data exfiltration and potential financial gain.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB