NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026) — Threadlinqs Intelligence
As of 2026-06-09, NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026) is a high-severity malware threat attributed to NSO Group (Israel), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0728 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: NSO Group · Israel · ESPIONAGE
On June 8, 2026 Meta filed a federal contempt-of-court motion alleging NSO Group violated the October 2025 permanent injunction (entered after WhatsApp's 2025 trial win and $168M judgment) by running
Meta/WhatsApp disclosed and disrupted a fresh social-engineering campaign it attributes to commercial-spyware vendor NSO Group, the developer of the Pegasus mercenary surveillance platform. According to Meta's June 8, 2026 contempt filing, attackers attempted to trick WhatsApp users into clicking malicious links that drove them to external websites outside of WhatsApp — a delivery pattern Meta describes as 'similar to previously reported 1-click phishing campaigns linked to NSO.' As part of the operation, NSO-linked actors created test accounts and groups on WhatsApp that Meta subsequently identified and removed. WhatsApp shared threat indicators so potential targets could determine whether they had been approached via text message, email, WhatsApp message, or other channels.
The campaign is significant because it allegedly continues conduct already barred by a U.S. court. WhatsApp won its civil suit against NSO Group, securing roughly $168 million in damages (later reduced on review) and, in October 2025, a permanent injunction restraining NSO from targeting WhatsApp infrastructure and users. NSO Group is appealing. A contempt motion asks the same court to enforce its existing injunction with coercive sanctions — potential fines, asset actions, or other penalties — rather than starting a new case. Meta tied the filing to broader policy advocacy, arguing that easing restrictions on NSO would undermine U.S. national security, and noting NSO Group's placement on the U.S. Commerce Department Entity List since November 2021. Citizen Lab researcher John Scott-Railton commented that 'NSO's own actions make the strongest argument for why they should stay on the Entity list.'
The operation echoes a long, well-documented history of NSO Pegasus deployment against journalists, lawyers, and human-rights defenders. Pegasus has historically been delivered via WhatsApp through the 2019 zero-click VOIP exploit (CVE-2019-3568) that NSO used against more than 1,400 devices in a two-week window, and via Apple iMessage zero-click/one-click exploit chains including KISMET, FORCEDENTRY (CVE-2021-30860), FINDMYPWN, PWNYOURHOME, and BLASTPASS (CVE-2023-41064 / CVE-2023-41061). A 2024 Access Now / Citizen Lab investigation documented at least 35 Jordanian journalists, activists, and human-rights lawyers targeted between 2019 and 2023, frequently via malicious WhatsApp and SMS links sent by operators posing as journalists requesting interviews. The June 2026 campaign reuses the social-engineering and external-redirect tradecraft from those operations even though the specific exploit payload behind the 2026 links was not enumerated in public reporting.
No CVE, CVSS, or concrete network IOC was published for the 2026 campaign itself; WhatsApp privately distributed indicators to affected users. Defensive value therefore centers on behavioral detection of spearphishing-link social engineering on messaging platforms, attacker test-account/group creation patterns, redirects to attacker-controlled external sites, and the established Pegasus post-exploitation behaviors on compromised mobile devices.
Weaknesses (CWE)
CWE-787, CWE-122, CWE-1188
Target sectors: media and journalism, civil society / human rights, legal services, government, political dissidents, non-governmental organizations
Target regions: Middle East, North America, Europe, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2019-3568, CVE-2021-30860, CVE-2023-41064, CVE-2023-41061, T1598, T1589, T1583, T1583, T1585, T1588, T1588, T1566, T1660, T1456