Take what’s happening now between Meta’s WhatsApp and NSO Group, the Israeli spyware outfit. You’d think a huge loss in a U.S. court, like last year, when a federal jury slapped NSO with over $167 million in punitive damages (but Judge Phyllis Hamilton reduced it to ~$4 million in October 2025, considering it excessive), would bring some changes. But NSO is back in the shadows, barely skipping a beat. For them, legal “boundaries” might as well be expense line items.
So, how did we end up here? You have to rewind to 2019, when NSO exploited a buffer overflow in WhatsApp’s VOIP stack, dropping Pegasus spyware onto about 1,400 phones; users didn’t even have to answer the call. After a tough legal fight, WhatsApp got a permanent injunction stopping NSO from going after their users or infrastructure.
But paper boundaries don’t stop code or determined actors. According to court filings, WhatsApp says NSO kept pushing, building new attack routes, at one point, even working on malware codenamed “Erised” and “Heaven” while the lawsuit was still crawling through the courts.
That brings us to the latest attack. This time, it wasn’t a silent, technical exploit. It was good old-fashioned trickery. WhatsApp’s security team caught NSO-linked accounts running a spear-phishing campaign, a 1-click attack, not the zero-click variety Pegasus became famous for. The idea was simple: target a handful of people (less than 10, all in Jordan and Lebanon), lure them into clicking a poisoned link, and compromise their devices.
Luckily, nobody fell for it. Meta’s team cut off the attack before real damage hit. In the background, WhatsApp watched NSO spin up throwaway accounts and test groups, using them to plan out and rehearse attacks before aiming for the real targets. Once security admins noticed, those “staging areas” got destroyed quickly.
But here’s the part that should put every cybersecurity leader on edge: NSO’s persistence. Their CEO told the court straight up, they’re always hungry for new ways in. If one door closes, they’ll look for windows: browsers, core OS vulnerabilities, third-party apps.
One company can’t patrol the entire digital world, no matter their resources. Stopping state-linked spyware or for-profit surveillance takes an alliance. That’s why a dozen civil rights organizations filed amicus briefs to keep the legal heat on NSO. WhatsApp is also funding the Spyware Accountability Initiative and sticking with Citizen Lab, the research outfit whose work led Apple to patch over a billion devices against Pegasus-era threats.
If you defend a network or just want to protect high-value targets, start with visibility. Watch for these NSO-linked domains popping up in SMS, email, or messaging app traffic:
hxxps://ikhwancast[.]com
hxxps://ghazacast[.]com
hxxps://fr24cast[.]com
This isn’t going away. Commercial spyware keeps mutating. If you want to stay safe, you’ll have to be just as relentless and just as creative.









