WhatsApp Foils Pegasus Spyware Attack by NSO Group
Key Takeaways WhatsApp has identified and disrupted new spear-phishing attempts linked to the NSO Group, the Israeli spyware vendor. The campaigns targeted a small number of users in Jordan and...
Key Takeaways
- WhatsApp has identified and disrupted new spear-phishing attempts linked to the NSO Group, the Israeli spyware vendor.
- The campaigns targeted a small number of users in Jordan and Lebanon using one-click phishing techniques.
- WhatsApp is petitioning a U.S. federal court to hold NSO Group in contempt for violating a permanent injunction issued in 2023.
- No successful device compromises have been detected in this latest campaign.
WhatsApp, a Meta-owned messaging platform, has successfully identified and neutralized a series of spear-phishing operations directly attributed to the NSO Group, an Israeli spyware company previously blacklisted by the U.S. government. In response to these renewed targeting efforts, WhatsApp is now seeking a federal court order to declare NSO Group in contempt for breaching a permanent injunction enacted just last year.
Table Of Content
This legal action stems from a prior U.S. federal jury ruling in May 2023, which mandated NSO Group to pay substantial punitive damages of $167,254,000 and compensatory damages of $444,719 to WhatsApp. This judgment followed a 2019 campaign where NSO Group’s Pegasus spyware compromised approximately 1,400 WhatsApp users.
The original lawsuit, initiated after NSO Group exploited a buffer overflow vulnerability within WhatsApp’s VOIP stack to covertly deploy Pegasus spyware, culminated in a permanent injunction. This order explicitly prohibited NSO Group from any future targeting of WhatsApp and its user base.
NSO’s history of disregarding legal boundaries is well-documented. Court documents have previously revealed that the firm continued to develop sophisticated exploits, including malware vectors internally codenamed “Erised” and “Heaven,” even after the initial lawsuit against them was filed.
The latest investigation by WhatsApp, prompted by user reports, uncovered NSO-linked accounts attempting to entice individuals into clicking malicious external links. This “one-click” phishing methodology is a classic technique previously associated with NSO Group’s operations.
According to a Meta spokesperson, the recent campaign primarily focused on fewer than 10 users located in Jordan and Lebanon. The spokesperson further confirmed that no evidence of successful device compromise was detected. WhatsApp also proactively identified and dismantled test accounts and groups established by the threat actors to stage these attacks.
WhatsApp Disrupts NSO Attack
WhatsApp is currently petitioning the U.S. federal court to hold NSO Group in contempt of the permanent injunction. The company argues that these renewed targeting activities represent a direct and deliberate violation of a legally binding court order.
Even NSO Group’s CEO has acknowledged in court that the company actively pursues “vectors, or ways to access the phone” beyond WhatsApp, including through browsers, operating systems, and other third-party applications. This admission underscores the persistent and extensive nature of NSO’s surveillance-for-hire business model.
WhatsApp is not alone in its efforts to counter NSO Group. In May 2024, a coalition of 12 civil rights organizations submitted amicus briefs, offering their support for the permanent injunction against NSO’s appeal.
Furthermore, WhatsApp has made a significant financial contribution to the Spyware Accountability Initiative (SAI). This fund provides crucial support to forensic research organizations, advocacy groups, and user-support networks globally, combating the proliferation of commercial spyware.
Citizen Lab, a vital technical partner since 2019, has previously leveraged its extensive spyware research to trigger a security update from Apple, safeguarding over a billion devices worldwide.
Threat Indicators (IOCs)
The following malicious domains have been definitively linked to NSO-associated phishing infrastructure. Users and cybersecurity defenders are strongly advised to scan all communication platforms, including SMS, email, and messaging applications, for these indicators:
| Indicator Type | Value |
|---|---|
| Malicious Domain | hxxps://ikhwancast[.]com |
| Malicious Domain | hxxps://ghazacast[.]com |
| Malicious Domain | hxxps://fr24cast[.]com |
What You Should Do
- Remain vigilant for suspicious messages, especially those containing unsolicited links, even if they appear to come from known contacts.
- Never click on unfamiliar links in messages; instead, navigate directly to legitimate websites or applications.
- Ensure your WhatsApp application and operating system are updated to the latest versions to benefit from the most recent security patches.
- Enable two-factor authentication (2FA) on your WhatsApp account and other online services for an added layer of security.
- Report any suspicious activity or messages directly to WhatsApp through its in-app reporting features.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.