Privacy & Compliance

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order

The Meta-owned communications app is filing a federal court contempt order against NSO.

WhatsApp security

Meta-owned communications app WhatsApp says it recently detected and disrupted a spear-phishing attempt linked to spyware company NSO Group. The attack is allegedly in defiance of a court order that bars the spyware maker from targeting WhatsApp.

WhatsApp filed a lawsuit against NSO in 2019, after it came to light that a zero-day vulnerability had been exploited to deliver spyware to users.

In December 2024, a judge ruled that NSO is liable, and in May 2025 a jury ordered the spyware maker to pay more than $444,000 in compensatory damages and $167 million in punitive damages, which NSO appealed.

In October 2025, a judge reduced the punitive damages to $4 million, but WhatsApp was granted a permanent injunction barring NSO from hacking its users.

NSO has been seeking to overturn the order blocking it from targeting WhatsApp users, arguing that the company will “suffer irreparable harm”.

According to WhatsApp, the spyware maker has violated the permanent injunction. The messaging app reported on Monday that it had recently learned of a social engineering attack that attempted to trick users into clicking on malicious links.

Advertisement. Scroll to continue reading.

WhatsApp has only shared a few domains as an indicator of compromise (IoC), but says it was able to link the attack to NSO, pointing to similarities to previously reported one-click phishing campaigns tied to the spyware company.

WhatsApp says it also caught the attackers creating test accounts and groups. Those accounts and groups have been disabled, but further action is also being taken.

“We’re filing a federal court contempt order against NSO for violating a permanent injunction that barred them from ever targeting WhatsApp and its users,” WhatsApp said.

Nearly a dozen civil society organizations recently filed an amicus brief with the Ninth Circuit Court of Appeals to maintain the lower court’s permanent injunction forbidding NSO from targeting WhatsApp and its customers.

In addition, WhatsApp said on Monday that it’s making a “significant contribution” to the Spyware Accountability Initiative, a fund supporting work aimed at exposing, challenging, and stopping the abuse of spyware technology. 

Related: ‘DarkSword’ iOS Exploit Kit Used by State-Sponsored Hackers, Spyware Vendors

Related: New ‘ZeroDayRAT’ Spyware Kit Enables Total Compromise of iOS, Android Devices

Related: WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

Related: Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch

Related Content

Vulnerabilities

The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.

Cyberwarfare

Iran-linked hacking groups are turning to high-volume, low-impact cyberattacks, and AI is providing a boost.

Mobile & Wireless

Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.

Privacy

Meta does not plan on fixing the vulnerability because it involves the use of a modified client application.

Cybercrime

The social media giant has disabled more than 150,000 accounts powering scam centers in Asia.

Compliance

The devices have been added to the NATO Information Assurance Product Catalogue (NIAPC).

Malware & Threats

Available via Telegram, researchers warn ZeroDayRAT is a ‘complete mobile compromise toolkit’ comparable to kits normally requiring nation-state resources to develop.

Data Protection

New Strict Account Settings allow users to block attachments and media and silence calls from unknown people.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version