WhatsApp says it disrupted new NSO spyware phishing attacks
WhatsApp says it stopped NSO-linked spear-phishing attempts that tried to lure users to malicious external sites.
Intelligence analysis by GPT-5.4 Mini

Meta says WhatsApp investigated user reports, disrupted NSO-linked social engineering, and took down test accounts and groups used in the campaign. The company says the activity appears to violate a 2025 injunction against NSO Group.
WhatsApp says it spotted sneaky fake messages meant to trick people into opening bad links, like a baited fishing hook. It stopped those accounts and told people to keep their phones updated so spyware has fewer ways in.
Analysis
What happened
WhatsApp says it detected and disrupted spear-phishing activity it believes was linked to NSO Group after users reported social engineering attempts. According to Meta, the attackers tried to trick people into clicking malicious links that sent them to external websites outside WhatsApp, which resembles earlier one-click phishing campaigns tied to NSO.
Why NSO is notable
NSO Group is a commercial spyware vendor best known for Pegasus. The article says its tools have been used against politicians, activists, journalists, academics, and other high-interest targets. It also notes that NSO has been on the U.S. sanctions list since November 2021.
Legal and technical context
Meta says it previously won a permanent injunction against NSO in 2025, along with a finding of liability for 1,400 infections and a $167 million fine. Meta argues the newly detected activity still conflicts with that order. The company also says it caught NSO-linked actors creating test accounts and groups on WhatsApp and took them down.
Defensive guidance
Meta says end-to-end encryption protects messages and calls from Pegasus and similar spyware, but it still urges users to keep apps and operating systems updated. It specifically points Android users to Advanced Protection and iPhone users to Lockdown Mode, both of which are meant to shrink the attack surface for spyware.
Key points
- WhatsApp says it disrupted NSO-linked spear-phishing attempts after user reports.
- The campaign tried to lure targets to external websites through malicious links.
- Meta says it also found and removed test accounts and groups used by the attackers.
- The company argues the activity violates a 2025 court order against NSO Group.
- Meta told users to keep apps and operating systems updated and use platform hardening features.
If WhatsApp’s detection and takedown hold up, the campaign may lose reach quickly and users could be spared from clicking the malicious links. The incident also reinforces the value of app updates and built-in hardening modes like Advanced Protection and Lockdown Mode.
The attack suggests NSO-linked operators can still shift to social engineering even after sanctions and court action. If users miss the warning signs or fail to update devices, the phishing path can still lead them off-platform to spyware delivery sites.



