Meta Files Contempt Order Against NSO Group for Fresh WhatsApp Phishing Attack After $168M Verdict
Meta has detected and blocked a new NSO Group spear-phishing campaign targeting WhatsApp users and has filed a federal contempt order. NSO, already under a permanent injunction and a $168M damages order, is now accused of violating the court's ban directly.

A smartphone displaying a WhatsApp warning notification
Meta has disclosed that it detected and blocked a coordinated spear-phishing campaign linked to Israeli spyware vendor NSO Group, and has filed a federal court contempt order against the company for violating a permanent injunction that expressly barred it from targeting WhatsApp and its users. The attempted operation, described by Meta on Monday, involved NSO Group creating test accounts and groups on WhatsApp, then attempting to redirect users to external websites through malicious links. Meta confirmed that the accounts and associated infrastructure have been taken down. Three domains linked to the campaign have been identified: fr24cast.com, ghazacast.com, and ikhwancast.com.
The contempt filing follows a significant legal history. A US federal jury last year ordered NSO Group to pay Meta approximately $168 million in damages after finding it liable for exploiting WhatsApp server infrastructure to deploy Pegasus spyware against more than 1,400 individuals globally. A permanent injunction was subsequently issued, prohibiting NSO from any further targeting of the platform. Meta's position is that Monday's activity constitutes a direct violation of that order.
Why This Matters for the MENA Region
NSO Group's Pegasus spyware has an extensively documented history of deployment across the Middle East. Investigations by Citizen Lab and Amnesty International have documented its use against journalists, activists, lawyers, and government officials across multiple MENA countries. The technology has been linked to surveillance operations targeting individuals in the UAE, Saudi Arabia, Bahrain, Morocco, and other countries in the region.
The commercial model behind Pegasus means that government and state-adjacent entities, not NSO itself, determine who is targeted. The injunction and contempt proceedings constrain NSO's operational infrastructure but do not directly address the behaviour of its clients. For security teams and individuals in the Gulf who may be at elevated risk of targeted surveillance given their professional roles, this development is a signal that sophisticated mobile spyware operations continue regardless of ongoing litigation. The UAE Cyber Security Council's confirmed disruption of coordinated targeted campaigns against government and financial platforms in 2026, cited at the Government Cybersecurity Summit in Abu Dhabi this month, reflects how actively this threat category is being tracked at a national level across the Gulf.
What the New Attack Method Indicates
Meta describes the latest operation as spear-phishing designed to trick users into clicking malicious links leading to websites outside of WhatsApp, a technique similar to previously reported one-click phishing campaigns linked to NSO. This approach differs from the zero-click exploit vectors that characterised earlier Pegasus deployment, which required no user interaction to compromise a device. The shift toward link-based lures may reflect the impact of legal and operational pressure on NSO's technical capabilities, but it also represents a tactic that is harder to detect through platform-level monitoring alone. This pattern of adversaries pivoting to social-engineering-based access vectors when technical exploit routes face increased scrutiny mirrors the broader shift documented in the Check Point VPN campaign targeting GCC enterprises, where attackers used geolocation-matched infrastructure specifically designed to blend with expected regional traffic patterns and evade detection. Users who receive unexpected messages containing links, particularly those arriving from accounts that are new or outside their existing contact networks, should treat them with significant caution.
Protective Steps for High-Risk Users
WhatsApp users who believe they may be at elevated risk due to their professional or public profile can enable the platform's Strict Account Settings, which impose additional privacy controls designed to reduce attack surface. These include enforcing two-step verification, disabling link previews, restricting visibility of profile information, and limiting who can add the account to groups. The feature does not eliminate risk from sophisticated adversaries but meaningfully raises the bar for certain categories of targeted attack. Users in high-risk environments should also consider keeping both WhatsApp and their device operating system fully updated, and should report any suspicious contact activity through the app's reporting function. Meta confirmed that end-to-end encryption on personal messages and calls remains in place and was not compromised by this campaign.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.