MilikMilik

Meta Says NSO's Pegasus Spyware Is Still Targeting WhatsApp

Meta Says NSO's Pegasus Spyware Is Still Targeting WhatsApp
Interest|Mobile Apps

What NSO Pegasus Spyware Is and Why WhatsApp Is a Prime Target

NSO Pegasus spyware is a powerful surveillance tool that, once secretly installed on a smartphone, can read messages, activate the microphone and camera, and track a person’s location in real time without their knowledge. Meta says NSO Group, the company behind Pegasus, has again turned its focus to WhatsApp, running new phishing campaigns despite a court order telling it to stop. Pegasus attacks have historically used both invisible exploits and one-click traps delivered through messaging apps, making mobile messaging security a central concern for journalists, activists, lawyers, and public figures. Because WhatsApp is widely used and trusted, it is an attractive delivery channel for social-engineering messages that push victims to click malicious links. Understanding how NSO Pegasus spyware works, who it targets, and why WhatsApp is a recurring avenue for intrusion is the first step toward effective spyware protection tips that ordinary users can apply.

Meta Blocks New WhatsApp Phishing Attacks Linked to NSO Group

Meta reports that it recently detected and blocked fresh WhatsApp phishing attacks linked to NSO Group, describing them as spear-phishing attempts designed to trick users into tapping malicious links. These messages pushed targets toward external websites outside WhatsApp, echoing earlier one-click WhatsApp phishing attacks linked to NSO. Meta also says it dismantled test accounts and groups that NSO allegedly created on WhatsApp as part of this activity. Domains associated with the campaign include fr24cast[.]com, ghazacast[.]com, and ikhwancast[.]com, which Meta has now blocked. According to Meta, “WhatsApp users' personal messages and calls remain protected with default end-to-end encryption,” but encryption alone does not stop users from being deceived into visiting hostile sites. The company is urging users to keep apps and operating systems updated, and to report suspicious messages or links so that malicious campaigns can be identified and removed more quickly.

Meta Says NSO's Pegasus Spyware Is Still Targeting WhatsApp

From Injunctions to Contempt: Meta’s Legal Fight Against NSO

The latest campaign comes after WhatsApp won a major legal victory against NSO Group over earlier Pegasus attacks that compromised around 1,400 users in a single operation. A U.S. court ordered NSO to stop targeting WhatsApp and issued a permanent injunction; Meta now argues that NSO has violated that order and has filed a motion for contempt. In a separate ruling, NSO Group was fined approximately USD 168 million (approx. RM772,800,000) in monetary damages for exploiting WhatsApp servers to deploy Pegasus spyware. The company has also been placed on a U.S. Commerce Department blocklist over activities deemed contrary to national security and foreign policy interests. Despite repeated sanctions and lawsuits, Meta claims NSO continues to run surveillance-for-hire operations, illustrating how difficult it is for courts and regulators to constrain commercial spyware vendors once their tools are in the wild.

How Pegasus Works and Who Is Most at Risk

Pegasus is designed to be stealthy and invasive. Once it infects a phone, it can capture calls, texts, encrypted chats, photos, and contact lists, and can silently turn on the microphone and camera. Earlier campaigns have sometimes used zero-click exploits that require no interaction from the victim, alongside one-click WhatsApp phishing attacks that lure users to tap on crafted links. Investigations over the years have found Pegasus on the phones of journalists, opposition politicians, lawyers, and human rights defenders, showing that critics and watchdogs are frequent targets. NSO says it sells only to governments for crime and counterterrorism work, but evidence shows use against civil society instead. For Meta, repeated WhatsApp compromises are a direct threat to the privacy promises it markets to billions of users and a critical test of whether mobile messaging security can withstand well-funded surveillance-for-hire operators.

Practical Spyware Protection Tips for WhatsApp Users

While most people are unlikely to be singled out by NSO Pegasus spyware, everyone should strengthen their WhatsApp defenses against phishing and similar attacks. Start by treating unexpected messages with caution, especially if they include links or urge urgent action; verify the sender’s identity through a separate channel before clicking anything. Enable two-step verification inside WhatsApp to add a PIN to account logins, which helps protect against account takeover. For those at higher risk, Meta now offers strict account settings: two-step verification is enabled, link previews are disabled, profile details and status are limited to contacts or a chosen list, and only known contacts can add you to groups. Keeping your phone’s operating system and WhatsApp updated closes known vulnerabilities. Combined with careful link habits, these steps can improve your mobile messaging security and reduce your exposure to advanced spyware campaigns.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!