
Meta Accuses NSO Group of WhatsApp Spear Phishing, Seeks Contempt After Court Injunction
Key Takeaways
- Meta alleges NSO violated a permanent injunction by targeting WhatsApp users with spear-phishing.
- WhatsApp disrupted new NSO-linked spear-phishing campaigns; seeks contempt action.
- NSO Group is an Israeli Pegasus spyware vendor previously blacklisted by the U.S. government.
Meta seeks contempt
Meta accused NSO Group of violating a permanent injunction by continuing to target WhatsApp communications with spear phishing and social engineering attempts, and said it had applied to court for NSO to be held in contempt.
“Meta today accused spyware maker NSO Group of violating a court order that barred it from targeting users of WhatsApp”
WhatsApp said it caught and disrupted the latest NSO-linked campaign after investigating user reports, and Meta said the incidents involved attempts to trick people into clicking on malicious links that drove them to external websites outside of WhatsApp.
Meta also said it caught NSO creating test accounts and groups on WhatsApp, which it took down, and it published malicious domains as indicators of compromise including ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com.
Meta’s filing comes after a jury decision in early May forced NSO Group to pay damages for attacking users of WhatsApp and other platforms with Pegasus, with damages originally set to US$167 million ($237 million) and later reduced to US$4 million ($5.7 million).
Jordan-linked tactics
Meta said the campaign it disrupted resembled spyware infections that hit journalists and activists in Jordan from 2019 to 2023, and it described the tactic as trying to “trick people into clicking on malicious links to drive them to external websites outside of WhatsApp.”
In a separate account of the same dispute, The Record from Recorded Future News said WhatsApp accused NSO of deploying spearfishing attacks in violation of an October court order barring the firm from using the messaging app as an attack vector.

The Record also reported that WhatsApp said the latest attacks used social engineering techniques to “trick people into clicking on malicious links to drive them to external websites outside of WhatsApp,” and that NSO created test accounts and groups that WhatsApp removed.
Meta’s contempt push was framed by a researcher at the University of Toronto’s Citizen Lab, John Scott-Railton, who wrote that “NSO’s own actions make the strongest argument for why they should stay on the Entity list.”
What’s at stake
Meta argued that keeping NSO under U.S. restrictions is necessary because “When a malicious company on the US government’s Entity List continues to defy US courts, existing restrictions must remain firmly in place.”
“Meta said Monday that it caught a spearphishing campaign linked to spyware maker NSO Group despite a court injunction, prompting the tech giant to file a contempt-of-court complaint”
CyberScoop reported that Meta said easing restrictions would undermine U.S. national security and put “American companies and billions of people worldwide who depend on secure communications at risk,” while also noting lawmakers sought information about the federal government’s prospective use of NSO Group tech.
WhatsApp’s public-facing response included technical guidance that end-to-end encryption protects users’ messages and calls from Pegasus and other spyware, along with calls to update apps and operating systems for optimal protection.
In addition, WhatsApp urged users to enable features such as Android’s ‘Advanced Protection’ and iOS’s ‘Lockdown Mode,’ and it said the threat indicators it shared included the domains ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com for people to check whether they were targeted.
More on Technology and Science

SpaceX IPO Debuts On US Markets, Making Elon Musk The World’s First Trillionaire
30 sources compared

Google Sues China-Based Outsider Enterprise for Gemini-Driven Phishing Scams in New York
11 sources compared

Quantum Space Agrees to Go Public Via SPAC Merger With Inflection Point Acquisition Corp. VI
10 sources compared

Coinbase Launches Coinbase for Agents Platform for AI Assistants to Trade Crypto and Make Payments
14 sources compared