NSO Group WhatsApp spear-phishing campaign
Campaign
Summary
Hide ▲
Show ▼
NSO Group remains tied to a WhatsApp spear-phishing campaign that used malicious links to push targets to external websites outside the app. On June 8, WhatsApp said it successfully disrupted the activity, removed test accounts and groups, and published related domains including fr24cast[.]com, ghazacast[.]com, and ikhwancast[.]com. WhatsApp also asked a US court to hold the blacklisted spyware firm in contempt for violating a permanent injunction, keeping the pressure on a campaign already associated with Pegasus abuse and prior targeting of WhatsApp users.
Related Happenings
WhatsApp contempt motion against NSO Group
Regulatory/Legal Action
H score33
First: 09.06.2026 11:15
Last: 09.06.2026 11:15
Sources 1
How related:
WhatsApp has asked a US court to hold a blacklisted spyware firm in contempt, after claiming it has violated a permanent injunction banning it from targeting users.
About this happening:
WhatsApp moved the US court to hold NSO Group in contempt over a permanent injunction tied to spyware targeting of users. The company says NSO violated the order by us...
WhatsApp contempt motion against NSO Group
Regulatory/Legal ActionHow related: WhatsApp has asked a US court to hold a blacklisted spyware firm in contempt, after claiming it has violated a permanent injunction banning it from targeting users.
About this happening: WhatsApp moved the US court to hold NSO Group in contempt over a permanent injunction tied to spyware targeting of users. The company says NSO violated the order by us...
NCSC alert on messaging-app targeting of high-risk individuals
Public Sector Action
H score30
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The UK National Cyber Security Centre (NCSC) issued a March 31 alert warning that Russia-based actors were targeting high-risk individuals through messaging apps,...
NCSC alert on messaging-app targeting of high-risk individuals
Public Sector ActionAbout this happening: The UK National Cyber Security Centre (NCSC) issued a March 31 alert warning that Russia-based actors were targeting high-risk individuals through messaging apps,...
Augmented Marauder / Water Saci multi-pronged phishing campaign targeting Latin America and Europe
Campaign
H score38
First: 01.04.2026 15:36
Last: 01.04.2026 15:36
Sources 1
About this happening:
On 2026-04-01, Augmented Marauder / Water Saci were reported running a multi-pronged phishing campaign against Spanish-speaking users in organizations across Latin Ameri...
Augmented Marauder / Water Saci multi-pronged phishing campaign targeting Latin America and Europe
CampaignAbout this happening: On 2026-04-01, Augmented Marauder / Water Saci were reported running a multi-pronged phishing campaign against Spanish-speaking users in organizations across Latin Ameri...
FBI public warning on Signal and WhatsApp phishing
Public Sector Action
H score30
First: 20.03.2026 22:45
Last: 20.03.2026 22:45
Sources 1
About this happening:
The US Department of State is offering up to $10 million through the Rewards for Justice program for information that helps identify or locate UNC5792 and UNC422...
FBI public warning on Signal and WhatsApp phishing
Public Sector ActionAbout this happening: The US Department of State is offering up to $10 million through the Rewards for Justice program for information that helps identify or locate UNC5792 and UNC422...
Latest development: 29.06.2026 12:29
The US government offered up to $10 million for information leading to the identification of UNC5792 and UNC4221, Russian intelligence-linked threat actors targeting Signal and WhatsApp users by posing as automated support accounts and stealing verification codes or Backup Recovery Keys; CISA and the FBI warned that sharing a Backup Recovery Key can let the actor access historical private and group messages and potentially keep access after a new account is created with the same phone number.
SORVEPOTEL WhatsApp malware campaign spreads across Brazil
Campaign
H score31
First: 12.03.2026 19:31
Last: 12.03.2026 19:31
Sources 1
About this happening:
A WhatsApp malware campaign in Brazil is abusing trusted chats and WhatsApp Web to spread SORVEPOTEL on Windows desktops. The lure uses malicious ZIP attac...
SORVEPOTEL WhatsApp malware campaign spreads across Brazil
CampaignAbout this happening: A WhatsApp malware campaign in Brazil is abusing trusted chats and WhatsApp Web to spread SORVEPOTEL on Windows desktops. The lure uses malicious ZIP attac...
Timeline
-
08.06.2026 20:08 3 articles · 1mo ago
Meta blocks NSO Group spear-phishing attempts against WhatsApp users
Initial DisclosureMeta detected and blocked spear-phishing attempts linked to NSO Group that tried to lure WhatsApp users to external websites with malicious links. The company also removed NSO Group test accounts and groups on WhatsApp and identified related domains including fr24cast[.]com, ghazacast[.]com, and ikhwancast[.]com.
Show sources
- Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order — thehackernews.com — 08.06.2026 20:08
- Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order — thehackernews.com — 08.06.2026 20:08
- WhatsApp says it disrupted new NSO spyware phishing attacks — www.bleepingcomputer.com — 08.06.2026 21:40
-
08.06.2026 20:08 2 articles · 1mo ago
Meta files contempt order against NSO Group over WhatsApp targeting
Legal Policy Action UpdateMeta said it is filing a federal court contempt order against NSO Group for violating a permanent injunction that barred the company from targeting WhatsApp and its users. It also urged high-risk users to enable strict account settings, including two-step verification, turning off link previews, and limiting profile visibility and group adds to trusted contacts.
Show sources
- Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order — thehackernews.com — 08.06.2026 20:08
- WhatsApp Discovers NSO Group-Linked Spearphishing Attempts — www.infosecurity-magazine.com — 09.06.2026 11:15