Spear-phishing against encryption: NSO, WhatsApp and the battle for mobile security

Author: Published 4 min de lectura 161 reading

The images in this article were generated with artificial intelligence. How we publish

WhatsApp has announced that it blocked speed-phishing campaigns linked, according to its investigation, to the well-known Israeli spyware provider NSO Group, in the latest sample of how targeted threats have moved from pure technical exploits to more sophisticated social trickery. The company claims to have deactivated test accounts and groups used for the campaigns and has identified a number of domains as commitment indicators, a pattern consistent with "one click" attacks that redirect users to malicious external sites.

This episode comes in the context of a long controversy: NSO and its Pegasus tool have been involved in intrusions against journalists, activists and officials, and have been the subject of lawsuits and decisions. Meta got a permanent judicial order in 2025 which prohibits him from going to WhatsApp and its users, but the company maintains that this ban has not completely stopped the firm's attempts to find new access routes. Meta has also provided a public summary of her research and the mitigations applied in her official blog: the announcement of Meta.

Spear-phishing against encryption: NSO, WhatsApp and the battle for mobile security
Image generated with IA.

It is important to understand what protects end-to-end encryption and what does not: the E2E prevents external actors from reading messages in transit but does not prevent a compromised phone (for example, by using an explosion that installs spyware) from sharing screens, files or keys with a malicious operator. In other words, the vulnerability to which these types of campaigns point is the device itself and the user's decisions by clicking on links or running content.

The technique described - speed-phishing that induces the victim to open a link that leads to an external site of attack - is especially dangerous because it exploits trust and curiosity. The attackers create plausible appearances, false contacts or abbreviations that seem legitimate. In addition, the use of safe-looking domains and temporary infrastructure makes it difficult for defenders and cloud suppliers to immediately assign and take automatic action.

For users of high-risk mobile devices and for any person concerned about their safety, concrete and continuous measures should be implemented: keep the operating system and apps up to date, activate mechanisms designed to reduce the attack surface (e.g. Apple's lockdown Mode - and Google's Advanced Protection program), review apps permissions and avoid opening unsolicited links even if they arrive from known unverified contacts, and use off-band methods to confirm sensitive requests. Apple explains Lockdown Mode on its support website: Apple support: Lockdown Mode, and Google describes its advanced protection initiative here: Google Advanced Protection.

Spear-phishing against encryption: NSO, WhatsApp and the battle for mobile security
Image generated with IA.

Beyond the technical recommendations for users, this case highlights a greater tension: judicial orders and sanctions have an impact but are not a substitute for technical controls and international cooperation. Platformer providers can detect and block accounts and domains, but spyware providers adapt tactics and can search for new vectors, which requires a coordinated response between technology, regulatory and security forces to degrade attack infrastructure and pursue operators.

For media organizations, NGOs and security teams that protect people at risk, the defence should include regular resistance tests (phishing simulations and telemetry review), strict device management policies and response plans that consider the need to change devices or numbers when an infection is suspected. It is also critical that incidents be reported to platforms so that they can take down-streams and the authorities to create evidence to facilitate legal action.

Ultimately, the lesson is that mobile security is a composite layer: encryption, user hygiene, system hardening and institutional cooperation They must work together. The usual users can reduce their risk with good practices and the above-mentioned protections; those at the point of view must adopt additional defences and have specialized advice. The early detection and deactivation of malicious infrastructure by platforms is positive, but it does not replace the need for sustained technological and legal measures to contain commercial threats such as those attributed to NSO.

Coverage

Related

More news on the same subject.