Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order

0
Medium
Vulnerability
Published: Mon Jun 08 2026 (06/08/2026, 13:23:03 UTC)
Source: SecurityWeek

Description

WhatsApp has detected and disrupted a spear-phishing campaign linked to the spyware company NSO Group, which is alleged to have violated a permanent court injunction barring it from targeting WhatsApp users. The attack involved social engineering to trick users into clicking malicious links, and WhatsApp identified indicators tying the campaign to NSO based on similarities to prior phishing efforts. WhatsApp is filing a federal court contempt order against NSO for defying the no-hacking order. The spyware maker has previously been found liable and ordered to pay damages related to exploiting a zero-day vulnerability in WhatsApp. WhatsApp has disabled attacker-created test accounts and groups and is taking further action while supporting broader efforts to combat spyware abuse.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/08/2026, 13:33:42 UTC

Technical Analysis

WhatsApp, owned by Meta, has uncovered a spear-phishing attack linked to NSO Group, a spyware vendor previously barred by a permanent injunction from targeting WhatsApp users. The attack used social engineering to lure users into clicking malicious links, with WhatsApp linking the campaign to NSO based on domain indicators and tactics consistent with earlier NSO phishing operations. NSO was found liable in court for exploiting a zero-day vulnerability in WhatsApp and has been subject to damages and an injunction since 2019. Despite this, NSO allegedly violated the court order, prompting WhatsApp to file a contempt motion. WhatsApp has disabled malicious accounts and groups created by the attackers and is contributing to initiatives aimed at exposing and stopping spyware misuse.

Potential Impact

The impact involves the attempted compromise of WhatsApp users through spear-phishing linked to NSO Group, which could lead to spyware installation if successful. The attack represents a violation of a court injunction intended to protect WhatsApp users from NSO's targeting. While WhatsApp disrupted the attack and disabled malicious infrastructure, the incident highlights ongoing risks from sophisticated spyware vendors exploiting social engineering. No confirmed widespread exploitation or zero-day vulnerability exploitation in this specific campaign is reported in the provided data.

Mitigation Recommendations

WhatsApp has already disrupted the attack, disabled malicious accounts and groups, and is pursuing legal action against NSO for contempt of court. Users should remain cautious of unsolicited links and phishing attempts. Since this is a targeted social engineering attack linked to a known spyware vendor, no additional specific technical mitigations are provided. WhatsApp’s legal and technical measures are the primary response. Patch status is not applicable as this is not a software vulnerability but an attack campaign. Users should keep WhatsApp updated and follow best practices for phishing avoidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/whatsapp-catches-spyware-firm-nso-defying-no-hacking-court-order/","fetched":true,"fetchedAt":"2026-06-08T13:33:34.650Z","wordCount":1102}

Threat ID: 6a26c4aee29bf47b50e9cfa2

Added to database: 6/8/2026, 1:33:34 PM

Last enriched: 6/8/2026, 1:33:42 PM

Last updated: 6/8/2026, 2:51:58 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses