Meta says it has disrupted a new campaign of WhatsApp phishing attacks linked to spyware vendor NSO Group. The company claims the activity violated a court order that permanently prohibited NSO from targeting WhatsApp users after a lengthy legal battle over the deployment of Pegasus spyware.
The latest discovery suggests that efforts to target WhatsApp users have continued despite legal restrictions, prompting Meta to seek additional action against the Israeli surveillance firm.
Meta Identifies New Targeting Activity
According to Meta, its security teams recently uncovered a phishing operation that used WhatsApp as part of a broader targeting campaign. The company said the attackers attempted to lure individuals into interacting with malicious content through carefully crafted messages.
Investigators linked the activity to infrastructure associated with NSO Group. Meta believes the campaign formed part of a surveillance operation aimed at gathering information from selected targets.
The company did not disclose the full number of people targeted. However, it stated that affected individuals were notified and that the malicious infrastructure was disrupted.
Court Order at Center of Dispute
The discovery carries additional significance because of Meta’s previous legal victory against NSO Group.
In 2024, a U.S. court ruled in favor of WhatsApp after finding that NSO had violated federal and California laws by using the messaging platform to deploy spyware. The ruling permanently barred the company from accessing or targeting WhatsApp services.
Meta now argues that the newly identified activity directly conflicts with that injunction. The company has asked the court to examine the new evidence and determine whether further action is warranted.
The case remains one of the most closely watched legal battles involving the commercial spyware industry.
Spyware Industry Faces Growing Pressure
The spyware market has faced increasing scrutiny from governments, technology companies, and privacy advocates in recent years.
Several vendors have come under investigation over allegations that surveillance tools were used against journalists, activists, political opponents, and other members of civil society. Security researchers have repeatedly warned that sophisticated spyware can provide extensive access to a victim’s communications and personal data.
Technology companies continue investing heavily in threat detection and monitoring as attackers shift tactics to avoid traditional security controls.
Conclusion
The latest WhatsApp phishing attacks highlight the ongoing challenges posed by commercial spyware operators. Despite court rulings and increased oversight, surveillance campaigns continue to emerge using new methods to reach potential targets.
Meta’s latest findings are likely to intensify scrutiny of the spyware industry while reinforcing the importance of monitoring and disrupting targeted phishing operations before they can compromise users.


0 responses to “WhatsApp Phishing Attacks Linked to NSO Group Disrupted”