WhatsApp Disrupts NSO-Linked Spyware Attacks and Seeks Contempt Order
WhatsApp says it has disrupted new spear-phishing attempts linked to NSO Group, the spyware company behind Pegasus, and is asking a U.S. federal court to hold NSO in contempt for allegedly violating a permanent injunction.
The new activity involved attempts to trick users into clicking malicious links that sent them outside WhatsApp. Meta said the campaign resembled earlier one-click phishing attacks tied to NSO and that WhatsApp also took down test accounts and groups used to stage the activity.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
In its WhatsApp spyware update, Meta said the court order barred NSO from targeting WhatsApp and its users again. The company now argues that the latest activity violated that order.
WhatsApp says NSO-linked accounts tried to lure users outside the app
The latest campaign did not rely on the 2019 WhatsApp calling exploit. Instead, WhatsApp described it as social engineering that pushed people toward malicious external websites.
That shift matters because it shows how commercial spyware operators can move from silent technical exploits to phishing when direct platform abuse becomes harder. A single click on a malicious link can still expose a high-risk user to spyware if the external site delivers an exploit chain.
Meta said NSO is already on the U.S. governmentโs Entity List. The Bureau of Industry and Security added NSO Group and Candiru to that list in 2021, citing spyware supplied to foreign governments and used to target officials, journalists, activists, academics, businesspeople, and embassy workers.
| Issue | What happened | Why it matters |
|---|---|---|
| New targeting | WhatsApp disrupted NSO-linked spear-phishing attempts. | The activity allegedly violated a court order. |
| Attack method | Targets were pushed toward malicious external links. | The campaign used social engineering instead of the old VoIP exploit. |
| Test infrastructure | WhatsApp found and removed test accounts and groups. | This suggests preparation inside the platform before targeting. |
| Legal response | Meta is seeking a federal contempt order. | The court could punish NSO if it finds a violation. |
| User risk | Pegasus can compromise phones and collect sensitive data. | High-risk users may need stronger account and device protections. |
The case traces back to the 2019 Pegasus attack
WhatsApp sued NSO in 2019 after the company said Pegasus spyware was used to target more than 1,400 WhatsApp users, including journalists, human rights workers, diplomats, and other members of civil society.
In 2025, WhatsApp won a landmark verdict against NSO. Meta said in its NSO verdict announcement that the case showed Pegasus could collect data from a compromised phone, including messages, emails, location information, microphone access, and camera access.
The case later produced a permanent injunction barring NSO from targeting WhatsApp and its users. That injunction is now at the center of Metaโs new request for contempt.
Civil rights groups are backing WhatsApp in the spyware fight
The legal fight has drawn support from civil rights groups, digital rights organizations, researchers, and press freedom advocates. In May 2026, the Knight First Amendment Institute filed an amicus brief in the WhatsApp v. NSO Group appeal.
The institute said the case concerns Pegasus, the Computer Fraud and Abuse Act, California law, and WhatsAppโs terms of service. It also argued that courts can hold companies accountable when they help develop or deploy spyware to access devices without authorization.
Meta said 12 prominent civil rights organizations, privacy advocates, security researchers, and digital rights experts joined the fight against NSOโs appeal. The broader concern is that commercial spyware can chill free expression, endanger journalists, and expose dissidents or activists to surveillance.
- WhatsApp says NSO-linked actors created test accounts and groups on the platform.
- The new campaign used malicious external links rather than the 2019 WhatsApp VoIP exploit.
- Meta is asking the court to hold NSO in contempt of the permanent injunction.
- The campaign adds pressure to the wider debate over mercenary spyware companies.
- High-risk users should update devices and enable stronger WhatsApp protections.
Meta says spyware remains a national security threat
Meta framed the latest activity as part of a larger surveillance-for-hire problem. It said NSOโs own CEO confirmed in court that the company looks for ways to access phones through browsers, operating systems, messaging apps, and other software.
The U.S. government reached a similar conclusion when it placed NSO on the Entity List. The Commerce Department notice said NSO and Candiru developed and supplied spyware later used to maliciously target civil society and government-related users.
Meta also said it is donating to the Spyware Accountability Initiative, a global fund that supports civil society groups working on forensic research, user support, advocacy, and accountability for spyware abuse.
| Organization or source | Role in the issue |
|---|---|
| Detected and disrupted NSO-linked spear-phishing attempts. | |
| Meta | Filed for a contempt order and is funding anti-spyware work. |
| NSO Group | Developer of Pegasus spyware and defendant in the WhatsApp case. |
| U.S. Commerce Department | Placed NSO on the Entity List in 2021. |
| Civil rights groups | Filed briefs supporting the injunction against NSO. |
| Spyware Accountability Initiative | Funds organizations investigating and challenging spyware abuse. |
Threat indicators linked to the campaign
Meta shared indicators so users and defenders can check for possible targeting across WhatsApp, SMS, email, and other messaging channels. These indicators should be treated as suspicious and investigated in context.
| Indicator type | Value |
|---|---|
| Malicious domain | ikhwancast[.]com |
| Malicious domain | ghazacast[.]com |
| Malicious domain | fr24cast[.]com |
Organizations should search mail logs, DNS logs, proxy logs, mobile security telemetry, and endpoint data for these domains. High-risk users should also review suspicious messages that encouraged them to open outside links.
How WhatsApp users can reduce Pegasus-style spyware risk
WhatsApp said personal messages and calls remain protected by default end-to-end encryption, but encryption does not stop spyware that compromises the device itself. If spyware infects a phone, it can potentially access data after it appears on the device.
Users who face elevated risk should update WhatsApp, update their phone operating system, avoid unexpected links, and report suspicious messages. WhatsApp also recommends Strict account settings for people who may be targeted by sophisticated attacks.
Strict account settings reduce the accountโs attack surface by enabling several privacy and security controls at once. These include two-step verification, disabled link previews, tighter profile visibility, and stricter group-add settings.
- Do not open unexpected links, even if they arrive from a known contact.
- Update WhatsApp and the phoneโs operating system as soon as updates are available.
- Enable two-step verification for WhatsApp.
- Use WhatsApp Strict account settings if you may face targeted spyware risk.
- Report suspicious WhatsApp messages directly in the app.
- Ask a trusted security professional for help if you work in journalism, human rights, politics, diplomacy, law, or civil society and believe you were targeted.
The latest Meta update shows that spyware vendors can keep adapting even after lawsuits, platform takedowns, and court orders. The companyโs response also shows that litigation has become part of the cybersecurity toolkit against surveillance-for-hire firms.
The case is not only about WhatsApp. The WhatsApp v. NSO Group case has become a wider test of whether U.S. courts can limit commercial spyware companies that develop or deploy tools used to break into phones.
For defenders, the lesson is direct. Spyware attacks often start with social engineering, but the damage happens at the device level. Stronger account settings, rapid patching, link caution, threat reporting, and legal pressure all matter in reducing the risk.
Meta says the 2025 spyware verdict was only one step. Its new contempt request signals that WhatsApp intends to keep using technical enforcement and court action when it believes NSO or similar spyware firms target its users again.
The companyโs funding for the Spyware Accountability Initiative also reflects a larger strategy: support researchers and advocacy groups that can identify infections, help victims, and push for stronger accountability across the spyware industry.
FAQ
WhatsApp says it disrupted spear-phishing attempts linked to NSO Group. The attackers tried to lure users into clicking malicious links that led to external websites outside WhatsApp.
NSO Group is an Israeli spyware company best known for Pegasus, a commercial spyware tool that can compromise smartphones and collect sensitive data from infected devices.
Meta says the new NSO-linked targeting attempts violated a permanent injunction that barred NSO from targeting WhatsApp and its users. Meta is asking a federal court to hold NSO in contempt of that order.
Meta says WhatsApp messages and calls remain protected by default end-to-end encryption. However, spyware can still threaten users if it compromises the device itself, because it may access information after it appears on the phone.
The shared indicators are ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com. Users and defenders should check these domains across WhatsApp, SMS, email, proxy logs, DNS logs, and other messaging platforms.
Users should keep WhatsApp and their phone operating system updated, avoid unexpected links, report suspicious messages, enable two-step verification, and use WhatsApp Strict account settings if they face elevated risk from targeted cyberattacks.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages