Cybernews WhatsApp Files Contempt Against NSO Group for New Spyware Attacks
Article Content
- •WhatsApp has filed a contempt order against NSO Group for violating a court injunction.
- •The recent phishing campaign targeted fewer than 10 users, primarily in Jordan and Lebanon.
- •WhatsApp has shared malicious domains linked to the attacks to assist users and researchers.
WhatsApp has filed a federal court contempt order against NSO Group for allegedly violating a permanent injunction that prohibits the spyware firm from targeting its users. The Meta-owned messaging platform disrupted new spear phishing attempts linked to NSO, which involved tricking users into clicking malicious links that redirected them to external websites. WhatsApp identified and dismantled test accounts created by NSO on its platform. The attacks are reminiscent of previous phishing campaigns associated with NSO's Pegasus spyware. The recent campaign reportedly targeted fewer than 10 users, primarily in Jordan and Lebanon, but no signs of compromise were detected among them. WhatsApp has publicly disclosed malicious domains related to the phishing attempts to aid users and security researchers. The ongoing legal battle follows a 2025 court ruling that found NSO liable for hacking over 1,400 WhatsApp users, resulting in a reduced damages award from $167 million to $4 million. The case highlights the persistent threat posed by commercial spyware firms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (62)
Following this threat?
Track Pegasus and Apple in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Serbian Activists Targeted by Advanced Spyware Ahead of Elections Since December 2025, at least 14 individuals in Serbia, including student activists and opposition politicians, have been targeted with advanced spyware, marking the largest documented wave of such surveillance in the country. The attacks coincide with local elections held on March 29, 2026, and are linked to the use…