WhatsApp Says NSO Broke Court Order With New Spyware Attacks
Updated:
WhatsApp has accused spyware maker NSO Group of targeting its users again, despite a permanent US court order banning the company from doing so. The Meta-owned messaging app says it has disrupted recent spear-phishing attempts linked to NSO and is now asking a federal court to hold the company in contempt.
Users Allegedly Targeted With Malicious Links
The alleged activity involved attempts to trick people into clicking malicious links that led them to websites outside WhatsApp. Meta said the campaign resembled previous one-click phishing attacks connected to NSO. WhatsApp also said it found test accounts and groups created on its platform, which have since been removed.
NSO Group is best known for Pegasus, a powerful spyware tool that has reportedly been used to target phones belonging to journalists, activists, government officials, military personnel and others. Spyware like this can be used to access private messages, calls, photos, location data and other sensitive information once a device is compromised.
A Long-Running Legal Battle
The dispute between WhatsApp and NSO dates back to 2019, when WhatsApp sued the company after a vulnerability was allegedly exploited to deliver spyware to users. In December 2024, a judge found NSO liable. In 2025, a jury awarded WhatsApp damages, while also issuing a permanent injunction that barred NSO from targeting WhatsApp or its users.
WhatsApp now says NSO violated that injunction. The company has shared several suspicious domains linked to the latest campaign, including ikhwancast[.]com, ghazacast[.]com and fr24cast[.]com, so security teams and other organizations can check for related activity.
Meta has not provided many technical details about the latest incident. It has not said how many users were targeted, whether any accounts were successfully compromised, or exactly when the activity took place. However, WhatsApp said the indicators and tactics were enough for it to link the attempts to NSO.
What This Means for WhatsApp Users
For everyday users, the incident is a reminder that even secure messaging apps can be used as a starting point for attacks. End-to-end encryption helps protect the content of WhatsApp messages and calls, but it does not stop someone from sending a dangerous link or trying to trick a user into leaving the app.
The safest approach is to treat unexpected links with caution, especially if they appear urgent, unusual or come from someone whose account may have been compromised. Users should avoid opening suspicious links, keep WhatsApp and their phone’s operating system updated, and report strange messages through the app.
Higher-Risk Users Should Take Extra Care
People who may be at higher risk, such as journalists, activists, political figures or human rights workers, should consider enabling stricter privacy and security settings like Lockdown Mode (iOS) or Advanced Protection (Android) . These protections can make devices and accounts harder to target and may reduce exposure to sophisticated attacks.
WhatsApp also said it is contributing to the Spyware Accountability Initiative, a fund that supports researchers and civil society groups working to uncover and challenge spyware abuse. The company described commercial spyware as a broader security threat, not just a privacy issue for individual users.
The case shows that legal action alone may not be enough to stop spyware activity. For consumers, the main takeaway is simple: encrypted messaging apps are good, but caution still matters. A single malicious link can be the first step in a much more serious attack.