The images in this article were generated with artificial intelligence. How we publish
Meta announced this week that it stopped speech-phishing attempts linked to the Israeli spyware provider NSO Group and that it will submit a contempt motion to a federal court for alleged violations of a court order that prohibits the group from going to WhatsApp and its users. According to the company, the attackers tried to deceive people to click on malicious links that redirected to external sites, a tactic that recalls the "1-click phishing" campaigns previously attributed to NSO and that also involved the creation of accounts and test groups in WhatsApp that Meta eliminated.
It is important to distinguish between the protection provided by end-to-end encryption and the exposure that causes attacks on the user's device. Encryption protects transit content but does not prevent an attacker from compromising a phone by means of a malicious link or invading software like Pegasus. Therefore, although WhatsApp emphasizes that messages and calls remain encrypted by default, the real threat to many victims is the infection of the device, not the interception of transit communication.

The detected maneuver included malicious domains identified by Meta, including fr24cast [.] com, ghazacast [.] com and ikhwancast [.] com, which were used as decoy. Technically, a 1-click phishing attack can work by exploiting vulnerabilities in apps or browsers to run code by just opening a link or a page, which drastically reduces the need for the victim to do more than a simple click. This capacity makes these attacks particularly dangerous for journalists, activists, officials and anyone in high-risk environments.
On the legal and policy level, the case adds another layer of pressure on NSO Group: last year the company was sentenced to pay damages for exploiting WhatsApp servers to deploy spyware against more than 1,400 people, and in 2021 it was included in the list of entities of the US Department of Commerce. United States for activities contrary to national security. Meta's tactic of requesting legal action shows that the large platforms combine technical detection with litigation to stop actors operating at the border between commercial marketing and illegal surveillance.

For users and security officials, practical recommendations remain the same but with a greater emphasis on advanced prevention: maintaining systems and applications always up to date, avoiding opening links received from unverified sources and reporting any suspicious activity to the platform. In addition, WhatsApp offers an option for "Strict account settings"- a hard configuration mode that limits who can see and contact the account - and other protections such as disable previous link views and activating verification in two steps; official information about these measures is available on the WhatsApp security page https: / / www.Whatsapp.com / security.
Those who consider their profile to be a potential target should raise their controls: activate double factor authentication preferably with physical keys, limit the visibility of the profile information, restrict who can add them to groups and consider the advice of mobile device analysis specialists. Organizations and journalists investigating spyware threats can also benefit from public resources and forensic studies on Pegasus and vectors of infection, for example Citizen Lab which document techniques and evidence used by surveillance companies.
Ultimately, this episode stresses that the fight against commercial spyware requires a combined response: continuous improvements in the technical security of platforms, regulatory and judicial updates that criminalize abuse, and stricter digital hygiene practices by users and organizations. Update, restrict and verify remain the basic rules for reducing the area of attack, but in cases of high risk effective protection requires proactive measures and, where appropriate, forensic and legal support.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...