Meta is seeking a federal contempt order against NSO Group after detecting new spear-phishing attempts and unauthorized account activity targeting WhatsApp users in violation of a permanent injunction.
Key Points
- Meta identified malicious domains, including fr24cast.com and ghazacast.com, used by NSO Group to facilitate phishing attacks against WhatsApp users.
- The company discovered and removed unauthorized test accounts and groups created by the spyware vendor on the platform.
- NSO Group remains under a permanent injunction following a 2023 court ruling that ordered $168 million in damages for previous Pegasus spyware exploits.
- Meta recommends that high-risk users enable "Strict account settings" to limit account visibility and reduce the potential attack surface.
- The U.S. Commerce Department previously added NSO Group to a national security blocklist in 2021 due to the company's involvement in malicious cyber activities.