NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)
NSO Group Pegasus Spyware (TL-2026-0728), also tracked as Meta v. NSO contempt complaint (June 2026), is a high-severity malware campaign, first published 2026-06-09. It is attributed to NSO Group (Israel) with high confidence, affects WhatsApp / Meta WhatsApp Messenger, references 4 CVEs (CVE-2019-3568, CVE-2021-30860, CVE-2023-41064), maps to 23 MITRE ATT&CK techniques (T1070, T1071, T1203), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0728
- Threat ID
- TL-2026-0728
- Also known as
- Meta v. NSO contempt complaint (June 2026), WhatsApp Pegasus targeting 2026
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-09
- Last reviewed
- 2026-06-09
- Attribution
- NSO Group
- Attribution confidence
- HIGH
- Nation-state nexus
- Israel
- Motivation
- ESPIONAGE
- Target sectors
- media and journalism, civil society / human rights, legal services, government, political dissidents, non-governmental organizations
- Target regions
- Middle East, North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in NSO Group Pegasus Spyware
Malware and tooling: Chrysaor, Chrysaor, Pegasus Installation/C&C server: HTTPS on TCP/443 with a unique per-operator domain and TLS certificate
On June 8, 2026 Meta filed a federal contempt-of-court motion alleging NSO Group violated the October 2025 permanent injunction (entered after WhatsApp's 2025 trial win and $168M judgment) by running a new spearphishing campaign against WhatsApp users. The activity used social-engineering messages with malicious links redirecting victims to external attacker-controlled websites — consistent with prior 1-click NSO Pegasus delivery — and involved attacker-created WhatsApp test accounts and groups that were later removed.
How NSO Group Pegasus Spyware works
Meta/WhatsApp disclosed and disrupted a fresh social-engineering campaign it attributes to commercial-spyware vendor NSO Group, the developer of the Pegasus mercenary surveillance platform. According to Meta's June 8, 2026 contempt filing, attackers attempted to trick WhatsApp users into clicking malicious links that drove them to external websites outside of WhatsApp — a delivery pattern Meta describes as 'similar to previously reported 1-click phishing campaigns linked to NSO.' As part of the operation, NSO-linked actors created test accounts and groups on WhatsApp that Meta subsequently identified and removed. WhatsApp shared threat indicators so potential targets could determine whether they had been approached via text message, email, WhatsApp message, or other channels.
The campaign is significant because it allegedly continues conduct already barred by a U.S. court. WhatsApp won its civil suit against NSO Group, securing roughly $168 million in damages (later reduced on review) and, in October 2025, a permanent injunction restraining NSO from targeting WhatsApp infrastructure and users. NSO Group is appealing. A contempt motion asks the same court to enforce its existing injunction with coercive sanctions — potential fines, asset actions, or other penalties — rather than starting a new case. Meta tied the filing to broader policy advocacy, arguing that easing restrictions on NSO would undermine U.S. national security, and noting NSO Group's placement on the U.S. Commerce Department Entity List since November 2021. Citizen Lab researcher John Scott-Railton commented that 'NSO's own actions make the strongest argument for why they should stay on the Entity list.'
The operation echoes a long, well-documented history of NSO Pegasus deployment against journalists, lawyers, and human-rights defenders. Pegasus has historically been delivered via WhatsApp through the 2019 zero-click VOIP exploit (CVE-2019-3568) that NSO used against more than 1,400 devices in a two-week window, and via Apple iMessage zero-click/one-click exploit chains including KISMET, FORCEDENTRY (CVE-2021-30860), FINDMYPWN, PWNYOURHOME, and BLASTPASS (CVE-2023-41064 / CVE-2023-41061). A 2024 Access Now / Citizen Lab investigation documented at least 35 Jordanian journalists, activists, and human-rights lawyers targeted between 2019 and 2023, frequently via malicious WhatsApp and SMS links sent by operators posing as journalists requesting interviews. The June 2026 campaign reuses the social-engineering and external-redirect tradecraft from those operations even though the specific exploit payload behind the 2026 links was not enumerated in public reporting.
No CVE, CVSS, or concrete network IOC was published for the 2026 campaign itself; WhatsApp privately distributed indicators to affected users. Defensive value therefore centers on behavioral detection of spearphishing-link social engineering on messaging platforms, attacker test-account/group creation patterns, redirects to attacker-controlled external sites, and the established Pegasus post-exploitation behaviors on compromised mobile devices.
MITRE ATT&CK techniques used in TL-2026-0728
Defense Evasion
T1070 Indicator Removal; T1628 Hide Artifacts; T1630 Indicator Removal on Host
Command and Control
T1071 Application Layer Protocol; T1437 Application Layer Protocol; T1573 Encrypted Channel
Execution
T1203 Exploitation for Client Execution; T1658 Exploitation for Client Execution
Collection
T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1636 Protected User Data
Credential Access
Discovery
T1426 System Information Discovery
Initial Access
T1456 Drive-By Compromise; T1566 Phishing; T1660 Phishing
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Exfiltration
Affected products and versions in NSO Group Pegasus Spyware
- WhatsApp / Meta — WhatsApp Messenger
Vulnerable versions: WhatsApp Android < 2.19.134 (CVE-2019-3568); WhatsApp iOS < 2.19.51; WhatsApp Business Android < 2.19.44
Fixed in: WhatsApp Android 2.19.134+; WhatsApp iOS 2.19.51+ - Apple — iOS / iMessage
Vulnerable versions: iOS < 14.8 (FORCEDENTRY / CVE-2021-30860); iOS <= 16.6 (BLASTPASS / CVE-2023-41064, CVE-2023-41061)
Fixed in: iOS 14.8; iOS 16.6.1 - Various — Targeted user populations (journalists, lawyers, activists, officials)
Vulnerable versions: WhatsApp users approached via spearphishing links and attacker test accounts/groups (2026 campaign)
Remediation for NSO Group Pegasus Spyware
Patches
- Keep WhatsApp / WhatsApp Business updated (historical fix for CVE-2019-3568 shipped in Android v2.19.134 / iOS v2.19.51).
- Keep iOS/macOS fully patched; FORCEDENTRY fixed in iOS 14.8 (CVE-2021-30860), BLASTPASS fixed in iOS 16.6.1 (CVE-2023-41064 / CVE-2023-41061).
Immediate actions
- Treat unsolicited WhatsApp/SMS/email messages containing links — especially those posing as journalists, recruiters, or officials requesting an interview or document review — as potential spyware lures; do not click.
- Apply the threat indicators WhatsApp distributed to affected users and review whether any household/staff device was approached via the campaign's channels.
- Enable Apple Lockdown Mode on high-risk iOS devices (journalists, lawyers, activists, executives, officials) — it blocks the known Pegasus iMessage zero-click vectors including BLASTPASS.
- Force-reboot at-risk mobile devices and rotate credentials/sessions for accounts accessed from them; many Pegasus chains do not survive a reboot but re-infection is common.
Workarounds
- Disable automatic media download and link previews in messaging apps for at-risk users.
- Route high-risk communications through hardened, minimal-surface devices and verify sender identity out-of-band before opening any link.
Longer-term hardening
- Deploy mobile threat defense / MDM with on-device behavioral detection for high-risk user populations.
- Establish a forensic process aligned to Amnesty International's MVT (Mobile Verification Toolkit) and Pegasus methodology for suspected-target devices.
- Adopt platform hardening (Lockdown Mode, minimized attack surface, disabling link previews) as policy for at-risk roles.
- Subscribe to and operationalize commercial-spyware threat indicators from Meta/WhatsApp, Citizen Lab, Amnesty Security Lab, and Apple threat notifications.
CVEs associated with NSO Group Pegasus Spyware
CVE-2019-3568, CVE-2021-30860, CVE-2023-41064, CVE-2023-41061
Weaknesses (CWE) in NSO Group Pegasus Spyware
CWE-787, CWE-122, CWE-1188
Timeline of NSO Group Pegasus Spyware
- WhatsApp discloses CVE-2019-3568, a zero-click VOIP buffer-overflow used by NSO Pegasus against 1,400+ devices; patched the same week.
- WhatsApp/Meta files its original civil suit against NSO Group and Q Cyber Technologies over the 2019 WhatsApp exploitation campaign.
- Citizen Lab publishes FORCEDENTRY (CVE-2021-30860), an NSO iMessage zero-click exploit; Apple patches in iOS 14.8.
- U.S. Commerce Department adds NSO Group to the Entity List for supplying spyware used to target journalists, activists, and officials.
- Citizen Lab discloses BLASTPASS (CVE-2023-41064 / CVE-2023-41061), an NSO iMessage zero-click PassKit exploit; Apple patches in iOS 16.6.1.
- Access Now and Citizen Lab document at least 35 Jordanian journalists, lawyers, and activists targeted with Pegasus (2019-2023) via WhatsApp/SMS malicious links.
- WhatsApp prevails at trial against NSO Group, with a jury awarding approximately $168 million in damages.
- A U.S. court enters a permanent injunction barring NSO Group from targeting WhatsApp users and infrastructure; NSO appeals.
- Meta files a contempt-of-court motion alleging a new NSO spearphishing campaign (malicious links to external sites, attacker test accounts/groups) violated the October 2025 injunction.
Sources cited for NSO Group Pegasus Spyware
- Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
- Meta claims NSO Group still targets WhatsApp users despite court order
- NVD — CVE-2019-3568 (WhatsApp VOIP buffer overflow)
- Facebook Security Advisory — CVE-2019-3568
- CISA Known Exploited Vulnerabilities Catalog — CVE-2019-3568
- Citizen Lab — BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
- Citizen Lab — FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- Citizen Lab — HIDE AND SEEK: Tracking NSO Group's Pegasus Spyware to Operations in 45 Countries
- Amnesty International — Forensic Methodology Report: How to catch NSO Group's Pegasus
- Access Now — New spyware attacks exposed: civil society targeted in Jordan
- The Hacker News — Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan
- Human Rights Watch — Spyware Targets Human Rights Watch Staff in Jordan
Threats related to NSO Group Pegasus Spyware
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets
Detection coverage for TL-2026-0728
As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0728 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.