WhatsApp has successfully detected and disrupted a new wave of spear phishing attempts linked to NSO Group, the Israeli spyware firm behind the Pegasus surveillance tool.
The Meta-owned messaging platform announced it is now pursuing a federal court contempt order against NSO for violating a permanent injunction that explicitly barred the company from ever targeting WhatsApp infrastructure or its users.
In May 2025, WhatsApp secured a landmark verdict against NSO Group, a company the U.S. Department of Commerce blacklisted in 2021 for engaging in activities contrary to U.S. national security interests.
The court ruling was unambiguous: NSO violated both federal and state hacking laws. The accompanying permanent injunction was intended to serve as a definitive legal barrier. WhatsApp now alleges NSO has brazenly violated that order, triggering the contempt filing.
WhatsApp Disrupts NSO Cyberattack
WhatsApp’s security team, acting on user reports, identified and shut down a multi-vector social engineering campaign operationally consistent with NSO’s previously documented tactics. The attack chain involved:
- Malicious link delivery — Adversaries attempted to redirect targets to external websites outside the WhatsApp ecosystem, consistent with 1-click phishing campaigns previously attributed to NSO and documented by Access Now in Jordan-based targeting operations
- Fake account and group creation — NSO-linked actors established test accounts and WhatsApp groups as staging infrastructure, all of which WhatsApp has since taken down
NSO’s CEO confirmed in court proceedings that the firm actively seeks “vectors, or ways to access the phone” beyond WhatsApp alone, including browsers, operating systems, and third-party applications, underscoring the breadth of the threat surface.
The case has attracted broad civil society support. Last month, 12 prominent civil rights organizations filed amicus briefs opposing NSO’s appeal of the permanent injunction.
WhatsApp is also making a significant financial contribution to the Spyware Accountability Initiative (SAI), a fund supporting forensic research, victim support, and advocacy organizations globally.
The initiative’s impact is demonstrable: a Citizen Lab zero-day discovery previously triggered an Apple security patch that reached over a billion devices, and a Greek court this year issued the first-ever criminal conviction of spyware company executives, built in part on Citizen Lab’s forensic evidence.
Threat Indicators (IOCs)
WhatsApp is publicly sharing the following malicious domains identified during the investigation to enable cross-platform detection. Security teams should flag or block these indicators in their environments:
hxxps://ikhwancast[.]comhxxps://ghazacast[.]comhxxps://fr24cast[.]com
These domains were used to deliver phishing payloads and may have been active across SMS, email, and other messaging vectors beyond WhatsApp.
WhatsApp urges all users to keep applications and devices updated and to report suspicious messages.
For individuals at elevated risk, journalists, government officials, and humanitarian workers, the platform strongly recommends enabling strict account protection settings. All personal messages and calls remain protected by default end-to-end encryption.
The contempt motion signals that even court-enforced restrictions may require active legal defense, reinforcing that no single company can neutralize the commercial spyware threat alone.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.