WhatsApp announced in June 2026 that it caught and disrupted a new spear phishing campaign linked to NSO Group, the Israeli spyware maker behind the Pegasus surveillance tool. The Meta-owned messaging app is now seeking to hold NSO in contempt of court, alleging the campaign violated a permanent injunction barring NSO from targeting WhatsApp and its users.
According to WhatsApp, the attackers attempted to trick users into clicking malicious links leading to external websites, where their devices could be infected with Pegasus spyware. WhatsApp said it also identified and removed test accounts and groups created by those behind the campaign. The investigation was prompted by reports from users.
The attacks were described as similar to a phishing campaign reported in Jordan in 2024, which also relied on malicious links to deliver NSO’s Pegasus spyware to targets.
The permanent injunction stems from a 2019 mass-hacking incident in which NSO targeted more than 1,400 WhatsApp users. WhatsApp notified victims and filed suit against NSO that same year. A jury subsequently ordered NSO to pay $167 million in damages, a figure later reduced to $4 million.
NSO Group did not respond to a request for comment from TechCrunch.
The new campaign adds to a long record of documented abuse tied to NSO’s spyware. Over the past decade, security researchers, journalists, and tech companies have linked Pegasus to the hacking of journalists, dissidents, human rights workers, and political opponents by government clients. The U.S. government has placed NSO on a Commerce Department blocklist and imposed sanctions on other spyware makers, including Intellexa.
A group of U.S. investors acquired NSO last year with stated plans to rehabilitate the company’s reputation and lobby for removal from the U.S. blocklist. As of the publication of this report, NSO remains on that list.
Source: TechCrunch