MilikMilik

Meta Says NSO Ignored WhatsApp Court Ban: What Users Must Know

Meta Says NSO Ignored WhatsApp Court Ban: What Users Must Know
Interest|Mobile Apps

What Meta Discovered About New NSO WhatsApp Attacks

The Meta–NSO WhatsApp dispute centers on Meta’s claim that NSO-linked operators continued spear-phishing attempts against WhatsApp users despite a federal court injunction, highlighting how commercial spyware vendors can keep probing popular messaging apps even after legal bans and why everyday users must treat WhatsApp phishing threats as an ongoing, high-risk security issue. Meta says its WhatsApp investigators recently detected and blocked a new NSO-linked campaign that tried to lure targets into clicking malicious links and leaving the app for attacker-controlled websites. The tactics mirrored previous “1‑click phishing” operations, where a single tap on the link could be enough to compromise a device. Meta also removed test accounts and groups that it says NSO created on WhatsApp. Although fewer than 10 users were targeted and none appear to have been successfully hacked, the episode shows that NSO WhatsApp attacks have evolved from server exploits to social engineering.

Meta Says NSO Ignored WhatsApp Court Ban: What Users Must Know

From Pegasus Verdict to Alleged Court Injunction Violations

Meta’s new legal move comes on the heels of its earlier Pegasus spyware security victory against NSO. A U.S. court previously found that NSO had violated U.S. laws by exploiting WhatsApp servers to deploy Pegasus against more than 1,400 people worldwide and imposed approximately USD 168 million (approx. RM772,000,000) in monetary damages. The same case produced a permanent injunction that bars NSO from targeting WhatsApp and its users. According to Meta’s latest filing, NSO’s fresh phishing activity violates that injunction, so Meta is now asking the federal court to hold the company in contempt. Although another judge later reduced the damages award, the ban on targeting WhatsApp remained in force. Meta argues that the alleged court injunction violations show how commercial surveillance firms may stay active against major platforms, even when courts attempt to shut them out.

How the New WhatsApp Phishing Threats Worked

The disrupted operation relied on classic spear-phishing techniques adapted to messaging apps. Attackers sent convincing messages designed to persuade specific targets to tap a malicious URL. Once clicked, the link would redirect the victim out of WhatsApp to attacker-controlled domains such as fr24cast[.]com, ghazacast[.]com, and ikhwancast[.]com. From there, browser or device exploits could potentially be triggered. The campaign reportedly focused on fewer than 10 individuals, primarily in Jordan and Lebanon, and Meta says it has found no evidence that any devices were successfully compromised. Still, the method matters: one message, one tap, and a device could be exposed. This approach sidesteps end-to-end encryption by attacking the phone itself, not the encrypted messages, which is why Pegasus spyware security concerns remain relevant even when chat content is encrypted by default on WhatsApp.

What This Means for Your Security on Messaging Apps

For ordinary users, the case underlines a simple fact: legal wins do not eliminate risk from advanced commercial spyware. Messaging platforms are an attractive entry point because attackers can abuse trusted notifications and contact lists to push tailored phishing lures. Meta highlighted court testimony that NSO pursues multiple paths into devices, including browsers, operating systems, and third-party apps like messaging services. End-to-end encryption still protects the content of your WhatsApp messages from being read in transit, but it does not stop someone from compromising your phone with a malicious link. That is why NSO WhatsApp attacks focus on device-level footholds rather than breaking encryption. Meta’s contribution to the Spyware Accountability Initiative and its publication of malicious domains show that platform security now extends beyond app code to tracking and disrupting wider spyware ecosystems.

Practical Steps to Protect Yourself Against WhatsApp Phishing

You can reduce your exposure to WhatsApp phishing threats with a few focused actions. First, keep WhatsApp, your browser, and your operating system updated so known security holes are patched. Be wary of unexpected links, even from contacts you recognise, and avoid tapping URLs that look unrelated to the conversation or use strange domain names. Meta also recommends enabling strict account settings if you think you face higher-than-average risk. This optional “lockdown-style” mode turns on two-step verification, disables link previews, and limits who can see your last seen, online status, profile photo, and About details. It also restricts who can add you to groups to contacts or a chosen list. These settings narrow the attack surface for targeted campaigns. Finally, report suspicious messages within WhatsApp so investigators can block emerging NSO WhatsApp attacks and other spyware operations before they spread.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!