Menu
Browse

Cyber Threat Actor: L.M.

Actor Type Location Known Incidents
 Icon
Hacker
China
1 incident
Profile

The threat actor known by the alias L.M. is associated with a location in China, as indicated in the available context. This actor came to public attention in February 2018 when they compromised the servers of TheTruthSpy, a consumer spyware company that markets Android and iOS monitoring applications. According to the actor’s own statements to a journalist, they gained administrative access after reverse‑engineering the company’s Android application and identifying a vulnerability that allowed them to query the media server for customer identifiers. Using this foothold, L.M. extracted usernames, passwords, intercepted communications, location data, and media files from more than ten thousand accounts, highlighting the firm’s storage of credentials in plaintext.

The actor’s tactics, as described in the interview, involved analyzing the spyware’s mobile client to uncover a server‑side weakness, then issuing web requests that returned sensitive information in clear text. A custom script automated the harvesting of credentials across the entire customer base, and the actor noted that they could have used the stolen logins to access victims’ external accounts such as email or payment services, although they claimed not to have taken any money. No other malware families, toolkits, or intrusion vectors are referenced in the source material, and no connections to state sponsors, criminal syndicates, or broader campaigns are documented. The TruthSpy breach remains the sole publicly reported operation attributed to L.M., serving as an illustration of how vulnerabilities in consumer‑focused surveillance products can be exploited to obtain large volumes of personal data. The actor’s later loss of access followed a server update by the targeted company, after which no further activity linked to L.M. was reported in the provided sources.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
1 source