WhatsApp Says It Disrupted New NSO-Linked Spyware Phishing Campaigns
WhatsApp says it disrupted new NSO-linked spear-phishing attempts that used malicious external links and test accounts to target users, highlighting the continued risk of commercial spyware campaigns despite prior sanctions, lawsuits, and court restrictions.
WhatsApp says it has disrupted a new wave of spear-phishing activity allegedly linked to NSO Group, the Israeli commercial spyware vendor behind the Pegasus surveillance platform.
According to Meta, WhatsApp’s parent company, the activity was identified after the company investigated user reports involving social engineering attempts. The attackers allegedly tried to trick targeted users into clicking malicious links that redirected them to external websites outside of WhatsApp.
Meta said the campaign resembled previously documented one-click phishing operations associated with NSO-linked spyware activity. Unlike zero-click exploits, which require no user interaction, one-click attacks rely on persuading the victim to open a malicious link that can deliver spyware or redirect the target into an exploit chain.
“We successfully disrupted NSO-linked social engineering attempts, after investigating user reports,” Meta said. “They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously reported 1-click phishing campaigns linked to NSO.”
Meta also said the attackers created test accounts and WhatsApp groups as part of the operation. Those accounts and groups were removed after detection.
The company published several domains as indicators of compromise connected to the activity:
ikhwancast[.]comghazacast[.]comfr24cast[.]com
NSO Group is best known for Pegasus, a highly advanced commercial spyware platform that has reportedly been used against journalists, activists, political figures, academics, lawyers, and other high-interest targets. Pegasus infections can give operators extensive access to a compromised mobile device, including messages, files, location data, microphone access, camera access, and other sensitive information.
NSO has faced sustained legal and regulatory pressure in recent years. The company was added to the U.S. Entity List in 2021 over concerns that its tools were supplied to foreign governments and used to target individuals and organizations, including people outside the countries where the spyware was operated.
Meta has also pursued NSO Group through the U.S. court system. In 2025, Meta secured a permanent injunction against the company, along with a liability finding tied to approximately 1,400 WhatsApp infections and a financial penalty of roughly $167 million.
Meta argues that the latest activity violates that court order, which bars NSO Group from targeting WhatsApp or its users. The company also highlighted broader national security concerns around commercial spyware vendors and their ability to develop or acquire new access methods across mobile platforms.
WhatsApp said its end-to-end encryption continues to protect message and call content from interception. However, encryption does not fully protect a user if their device itself is compromised by spyware. Once spyware gains control of a phone, it may be able to access content directly from the endpoint before or after encryption is applied.
That distinction is important for users at higher risk. Spyware attacks do not always break encryption directly. Instead, they often attempt to compromise the device, the browser, the operating system, or another app to gain access to sensitive data from inside the user’s environment.
WhatsApp is advising users to keep the app and their mobile operating systems fully updated. Security updates are especially important because commercial spyware operations often rely on exploiting recently discovered or privately held vulnerabilities in mobile platforms.
Users who may be at elevated risk, including journalists, activists, public officials, executives, legal professionals, and individuals involved in sensitive work, should consider enabling additional hardening features. On iOS, Apple’s Lockdown Mode reduces the attack surface by restricting certain features commonly abused by spyware. On Android, Google’s Advanced Protection offers stronger account and device security controls for users who may be targeted.
The incident shows that commercial spyware groups continue to adapt their tactics even after legal action, sanctions, and public exposure. While WhatsApp disrupted the observed campaign, the continued use of phishing infrastructure and test accounts suggests attackers are still probing for ways to reach high-value targets through social engineering and external exploit delivery.
Comments
0 public comments
No comments yet
Be the first to add a comment to this article.
Add a comment
Please sign in to comment on this article.
Sign In