# Meta Files Contempt Order Against NSO Group Over New WhatsApp Phishing Attacks
Meta has escalated its legal battle with NSO Group, filing a federal contempt order after detecting and blocking sophisticated spear-phishing campaigns targeting WhatsApp users. The Israeli spyware vendor's latest attempt to compromise the messaging platform directly violates a permanent injunction, marking a significant escalation in what has become a recurring pattern of evasion and non-compliance by the controversial surveillance firm.
## The Threat
On Monday, Meta announced it had detected and neutralized active phishing attacks originating from NSO Group infrastructure. The campaign employed a familiar playbook: attackers crafted deceptive messages designed to trick users into clicking malicious links that redirect to external websites impersonating WhatsApp services. These "1-click phishing" attempts represent a direct threat to users' account credentials and could serve as the first step toward account compromise or device infection.
Parallel to the phishing campaign, Meta security teams uncovered evidence that NSO Group operatives had created test accounts and groups directly on WhatsApp's platform. The company confirmed these accounts have been removed, but their presence indicates sustained technical reconnaissance of WhatsApp's infrastructure—suggesting NSO Group continues to probe for vulnerabilities and maintain operational presence on the platform despite previous legal restrictions.
The malicious domains associated with this campaign include:
These domains were likely designed to mimic legitimate WhatsApp interfaces, increasing the likelihood that unsuspecting users would enter credentials or sensitive information.
## Background and Context
This latest incident represents the fourth documented NSO Group violation of a permanent injunction issued by a U.S. federal court. The legal history between Meta and NSO Group spans nearly a decade, with the intensity of enforcement actions escalating significantly in recent years.
The Pegasus Spyware Campaign
In 2019, NSO Group used a zero-day vulnerability in WhatsApp's video calling service to deploy Pegasus spyware directly to target devices. The attack was remarkably efficient—requiring only a single missed call to infect a device with one of the world's most sophisticated surveillance tools. This vulnerability affected approximately 1,400 individuals globally, including journalists, human rights activists, government officials, and dissidents.
Previous Legal Actions
Last year (2025), a U.S. court found NSO Group liable for the Pegasus campaign and ordered the company to pay approximately $168 million in damages to Meta. This judgment represented one of the largest monetary penalties against the spyware vendor, though legal experts questioned whether it would meaningfully impact operations for a company with estimated annual revenues exceeding $1 billion at its peak.
Commerce Department Blocklist
In 2021, the U.S. Commerce Department added NSO Group to its Entity List, which restricts the company's access to American technology and components. The designation officially stated that NSO Group's activities were "contrary to the national security or foreign policy interests of the United States." This action was accompanied by parallel designations against other surveillance vendors, signaling a broader U.S. policy shift against private spyware companies.
The Contempt Filing
By filing a contempt order, Meta alleges NSO Group has willfully violated the permanent injunction barring it from targeting WhatsApp and its users. Contempt findings can result in substantial financial penalties and, in cases of willful violation, potential criminal referrals. This escalation signals Meta's frustration with repeated violations and suggests the company views litigation as increasingly ineffective at deterring NSO Group's behavior.
## Technical Details
The phishing infrastructure demonstrates that NSO Group has maintained technical sophistication despite international sanctions and legal pressure. Several technical elements deserve scrutiny:
Attack Vector: The 1-click phishing approach is lower-cost and lower-risk than exploiting zero-day vulnerabilities, but depends on social engineering—training users to click malicious links. This shift suggests NSO Group may be responding to increased device-level protections by pivoting toward credential harvesting and account takeover.
Domain Registration: The malicious domains employed straightforward homograph tactics—using legitimate-sounding broadcast-service names that could plausibly relate to WhatsApp. The choice of "cast" domains (fr24cast for France, ghazacast for Gaza, ikhwancast for Muslim Brotherhood) suggests targeting is geographically or ideologically specific, consistent with NSO Group's historical targeting patterns.
Account Creation: NSO Group's creation of test accounts and groups indicates active reconnaissance. These may have been used to evaluate detection systems, test payload delivery mechanisms, or identify accounts vulnerable to compromise. The discovery of test infrastructure suggests Meta's security monitoring capabilities have improved substantially since previous campaigns.
## Implications
Persistent Threat
This incident underscores that despite significant legal and regulatory pressure, NSO Group continues developing new attack methodologies and maintains operational capacity to threaten WhatsApp users. The company appears willing to accept repeated legal liability and financial penalties as a cost of doing business.
Targeting Profile
Based on historical targeting patterns and the geographic specificity of domain names, the campaigns likely target NSO Group's traditional victim profile: government officials, journalists, activists, and political opposition figures. However, phishing campaigns inherently lack precision—they may also compromise journalists, aid workers, and ordinary citizens mistaken for high-profile targets.
E2E Encryption Limitations
While Meta emphasized that WhatsApp's end-to-end encryption remains unbroken, this incident highlights an important limitation: encryption protects message contents, but account compromise enables adversaries to read older message archives, trigger password resets, install backup copies of messages, or pivot to targeted device compromise through other means.
## Recommendations
For WhatsApp Users
Meta recommends that users at elevated risk of sophisticated attacks enable Strict Account Settings, which implements a lockdown-style security posture:
For Organizations
Organizations with staff at heightened risk should:
For Policymakers
This incident demonstrates that export controls and financial penalties alone have proven insufficient to deter NSO Group. Policymakers should consider:
## HackWire Analysis
NSO Group's repeated violations of a permanent injunction reveal a troubling gap between legal accountability and operational deterrence. The company appears to have calculated that fines, export controls, and litigation represent acceptable business costs—particularly given the high-value intelligence that spyware deployments can yield for authoritarian clients. This cost-benefit analysis will shift only when penalties become existential threats to the company's operations, not merely grudging compliance.
What's particularly significant here is the shift in attack methodology. The Pegasus zero-day required extraordinary technical sophistication; phishing campaigns require social engineering and patience. This pivot suggests NSO Group may be responding to both increased device-level protections and the knowledge that zero-day exploits attract the most intense legal and diplomatic scrutiny. Phishing leaves more forensic breadcrumbs but scales more broadly and draws less geopolitical attention.
The timing is also instructive: this campaign launched exactly one year after the previous $168 million judgment. The pattern suggests NSO Group views annual compliance violations as periodic litigation costs rather than deterrents. Until enforcement mechanisms include personal consequences for decision-makers—not just corporate fines—or until export controls genuinely prevent component access, NSO Group's behavior is unlikely to change.
For defenders, the takeaway is clear: account security controls and basic hygiene (2FA, device updates) remain foundational. But they're also insufficient against nation-state-grade adversaries with unlimited budgets. High-risk users should assume compromise is inevitable and design their digital practices accordingly.
— HackWire Editorial
## Related Coverage