Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
Home/CyberSecurity News/WhatsApp Stops NSO Pegasus Spyware Attacks on Users
CyberSecurity News

WhatsApp Stops NSO Pegasus Spyware Attacks on Users

Meta’s WhatsApp has identified and disrupted a fresh wave of spear-phishing campaigns directly linked to NSO Group, the Israeli spyware firm blacklisted by the U.S. government. As a result, WhatsApp...

Marcus Rodriguez
Marcus Rodriguez
June 8, 2026 2 Min Read
23 0

Meta’s WhatsApp has identified and disrupted a fresh wave of spear-phishing campaigns directly linked to NSO Group, the Israeli spyware firm blacklisted by the U.S. government. As a result, WhatsApp is now petitioning a federal court to hold NSO Group in contempt for violating a permanent injunction issued just last year.

In May 2025, a U.S. federal jury ordered NSO Group to pay $167,254,000 in punitive damages and $444,719 in compensatory damages to WhatsApp following a 2019 campaign that compromised approximately 1,400 users.

That case which began when NSO exploited a buffer overflow vulnerability in WhatsApp’s VOIP stack to silently deliver Pegasus spyware resulted in a permanent injunction barring NSO from ever targeting WhatsApp and its users again.

NSO’s history of defiance is well-documented; court filings revealed the firm continued developing exploits including malware vectors codenamed “Erised” and “Heaven” even after the original lawsuit was filed.

WhatsApp’s latest investigation, triggered by user reports, uncovered NSO-linked accounts attempting to lure users into clicking on malicious external links, a classic 1-click phishing technique previously attributed to NSO Group.

The campaign primarily targeted fewer than 10 users in Jordan and Lebanon, according to a Meta spokesperson, who confirmed no signs of successful device compromise were detected. WhatsApp also identified and took down test accounts and groups created by threat actors to stage the attacks.

WhatsApp Disrupts NSO Attack

WhatsApp is now petitioning the U.S. federal court to hold NSO in contempt of the permanent injunction, arguing that the renewed targeting activity constitutes a direct and willful violation of a binding court order.

NSO’s own CEO has confirmed in court that the company actively seeks “vectors, or ways to access the phone” beyond WhatsApp — including browsers, operating systems, and third-party applications illustrating the persistent and expansive nature of its surveillance-for-hire operations.

WhatsApp is not fighting this battle alone. In May 2026, 12 civil rights organizations filed amicus briefs in support of the permanent injunction against NSO’s appeal.

WhatsApp has also made a significant financial contribution to the Spyware Accountability Initiative (SAI), a fund supporting forensic research organizations, advocacy groups, and user-support networks globally.

Citizen Lab, a key technical partner since 2019, previously leveraged its spyware research to trigger an Apple security update protecting over a billion devices.

Threat Indicators (IOCs)

The following malicious domains have been confirmed as linked to NSO-associated phishing infrastructure. Users and defenders are urged to scan across all platforms — SMS, email, and messaging apps:

Indicator Type Value
Malicious Domain hxxps://ikhwancast[.]com
Malicious Domain hxxps://ghazacast[.]com
Malicious Domain hxxps://fr24cast[.]com

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Chrome Patches 429 Vulnerabilities, 2 Including Critical

Next Post

UNC3753 Attacks US Law Firms via V Attacking Using

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us