What the New NSO WhatsApp Phishing Discovery Means
NSO WhatsApp phishing refers to spear‑phishing campaigns that abuse the messaging app’s trust and interface to trick users into clicking malicious links that redirect to attacker‑controlled websites, where exploits or spyware can be delivered to compromise devices despite end‑to‑end encryption protecting chats. Meta says its WhatsApp investigators recently detected and blocked a new NSO‑linked spear‑phishing attempt that targeted fewer than 10 users, mainly in Jordan and Lebanon, using one‑click links sent over chat. The campaign mirrored earlier social engineering tactics attributed to NSO, focusing on persuasive messages rather than technical vulnerabilities inside WhatsApp itself. Meta reports no evidence that any of the identified accounts were successfully compromised. Still, the incident underlines an ongoing Meta security threat: commercial surveillance vendors continue probing for ways to reach high‑value targets over popular messaging platforms even after high‑profile legal disputes and public scrutiny.

From Pegasus Spyware Ruling to Alleged Court Injunction Violation
The latest phishing activity comes after a landmark Pegasus spyware ruling against NSO Group. A U.S. court previously found that NSO had misused WhatsApp infrastructure to deploy Pegasus against more than 1,400 people, including journalists, activists, and dissidents, and ordered the company to pay approximately USD 168 million (approx. RM772,800,000) in damages. Although a judge later reduced the award to USD 4 million (approx. RM18,400,000), the permanent injunction blocking NSO from targeting WhatsApp or its users remained in force. According to Meta, NSO’s newly detected spear‑phishing attempts and the creation of test WhatsApp accounts and groups breach that order, amounting to a court injunction violation. “Last year, WhatsApp made history by securing a landmark verdict and permanent injunction barring NSO Group … from targeting WhatsApp and its users ever again,” Meta wrote, framing the fresh activity as a direct challenge to that ruling.
Meta’s Contempt Motion and What Comes Next for NSO
In response to the alleged NSO WhatsApp phishing push, Meta has filed a motion asking a federal court to hold NSO in contempt of the permanent injunction. If the court agrees that NSO violated the order, contempt proceedings could trigger additional penalties and stricter enforcement tools aimed at keeping the spyware vendor away from WhatsApp infrastructure and users. Possible outcomes range from monetary sanctions to tighter monitoring and clearer technical boundaries defined by the court. Meta is using the filing to spotlight commercial spyware as a national security and human rights concern, pointing to NSO leadership’s own testimony that the company seeks multiple paths into devices, including browsers, operating systems, and third‑party apps. The contempt case will test whether civil courts can meaningfully restrain commercial surveillance actors that operate across borders and target individuals in many regions.
Ongoing Risks to WhatsApp Users Despite Legal Wins
Even though Meta won a Pegasus spyware ruling and secured a permanent injunction, the latest NSO WhatsApp phishing attempts show that legal outcomes do not eliminate risk. Meta says it disrupted “1‑click phishing” style links and removed NSO‑linked test accounts, but messaging apps remain a prime target because people trust alerts and chat messages. To reduce exposure, Meta encourages users—especially those who think they may face sophisticated attacks—to enable strict account settings in WhatsApp. This lockdown mode turns on two‑step verification, disables link previews, restricts profile visibility to contacts or custom lists, and limits who can add you to groups. Meta also advises keeping apps and devices updated and reporting suspicious messages so investigators can act quickly. Combined with court action, these steps help shrink the attack surface while the broader fight over commercial spyware continues.






