Meta reports NSO Group continues targeting WhatsApp users

๐กUnderstand the evolving threat landscape of commercial spyware targeting major communication platforms.
โก 30-Second TL;DR
What Changed
Meta confirms NSO Group remains a threat to WhatsApp users.
Why It Matters
This highlights the critical importance of robust endpoint security and the vulnerability of even end-to-end encrypted platforms to sophisticated exploit chains.
What To Do Next
Review your organization's mobile device management (MDM) policies and ensure all communication apps are updated to the latest versions to mitigate known exploit vectors.
Key Points
- โขMeta confirms NSO Group remains a threat to WhatsApp users.
- โขThe report underscores the ongoing battle between encrypted platforms and commercial spyware vendors.
- โขSecurity teams must remain vigilant against advanced persistent threats (APTs) targeting messaging infrastructure.
๐ง Deep Insight
Web-grounded analysis with 16 cited sources.
๐ Enhanced Key Takeaways
- โขMeta is escalating its legal battle by filing a federal court contempt order against NSO Group, alleging violation of a permanent injunction that previously barred the spyware firm from targeting WhatsApp users.
- โขThe latest targeting attempts by NSO Group involved spear phishing campaigns, which aimed to trick WhatsApp users into clicking malicious links, and the creation of test accounts and groups on the platform.
- โขA US court previously awarded Meta $168 million in damages against NSO Group for hacking 1,400 WhatsApp users in 2019, a sum later reduced to $4 million, alongside a permanent injunction.
- โขNSO Group underwent a significant ownership change in 2025, transitioning to new US-based ownership and appointing a new Executive Chairman, with an stated aim to strengthen governance and strategically pivot towards providing lawful intercept tools for Western-aligned democracies.
๐ ๏ธ Technical Deep Dive
- Pegasus is spyware developed by NSO Group, designed for covert and remote installation on mobile phones running iOS and Android operating systems.
- It utilizes a suite of exploits, including sophisticated zero-click vulnerabilities, which allow infection without any interaction from the victim. Examples include exploiting vulnerabilities in WebKit (CVE-2016-4657) and messaging apps like WhatsApp or iMessage.
- Infection vectors can include clicking malicious links, or through zero-click methods leveraging vulnerabilities in apps such as Photos, Apple Music, and iMessage.
- Once installed, Pegasus can perform extensive surveillance, including reading text messages (even encrypted ones after device compromise), call snooping, collecting passwords, real-time location tracking via GPS, and remotely activating the device's microphone and camera.
- It can harvest a wide array of data from various applications, including iMessage, Gmail, Viber, Facebook, WhatsApp, Telegram, Skype, and Signal, as well as extracting contacts, call logs, photos, web browsing history, and device settings.
- The spyware is highly configurable, modular, employs strong encryption to evade detection, and includes self-destruct mechanisms.
- NSO Group's CEO has indicated that the company actively seeks various vectors to access phones beyond WhatsApp, targeting browsers, operating systems, and other applications.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (16)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates

Glow emerges from stealth at $1.2B valuation for AI security

OpenAI AI Escapes Sandbox and Breaches Hugging Face

New Malware Targets AI Infrastructure and Coding Systems

US outlines its $5 billion Genesis Mission to boost science
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Engadget โ