NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)

NSO Group Pegasus Spyware (TL-2026-0728), also tracked as Meta v. NSO contempt complaint (June 2026), is a high-severity malware campaign, first published 2026-06-09. It is attributed to NSO Group (Israel) with high confidence, affects WhatsApp / Meta WhatsApp Messenger, references 4 CVEs (CVE-2019-3568, CVE-2021-30860, CVE-2023-41064), maps to 23 MITRE ATT&CK techniques (T1070, T1071, T1203), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0728

Threat ID
TL-2026-0728
Also known as
Meta v. NSO contempt complaint (June 2026), WhatsApp Pegasus targeting 2026
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-09
Last reviewed
2026-06-09
Attribution
NSO Group
Attribution confidence
HIGH
Nation-state nexus
Israel
Motivation
ESPIONAGE
Target sectors
media and journalism, civil society / human rights, legal services, government, political dissidents, non-governmental organizations
Target regions
Middle East, North America, Europe, Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in NSO Group Pegasus Spyware

Malware and tooling: Chrysaor, Chrysaor, Pegasus Installation/C&C server: HTTPS on TCP/443 with a unique per-operator domain and TLS certificate

On June 8, 2026 Meta filed a federal contempt-of-court motion alleging NSO Group violated the October 2025 permanent injunction (entered after WhatsApp's 2025 trial win and $168M judgment) by running a new spearphishing campaign against WhatsApp users. The activity used social-engineering messages with malicious links redirecting victims to external attacker-controlled websites — consistent with prior 1-click NSO Pegasus delivery — and involved attacker-created WhatsApp test accounts and groups that were later removed.

How NSO Group Pegasus Spyware works

Meta/WhatsApp disclosed and disrupted a fresh social-engineering campaign it attributes to commercial-spyware vendor NSO Group, the developer of the Pegasus mercenary surveillance platform. According to Meta's June 8, 2026 contempt filing, attackers attempted to trick WhatsApp users into clicking malicious links that drove them to external websites outside of WhatsApp — a delivery pattern Meta describes as 'similar to previously reported 1-click phishing campaigns linked to NSO.' As part of the operation, NSO-linked actors created test accounts and groups on WhatsApp that Meta subsequently identified and removed. WhatsApp shared threat indicators so potential targets could determine whether they had been approached via text message, email, WhatsApp message, or other channels.

The campaign is significant because it allegedly continues conduct already barred by a U.S. court. WhatsApp won its civil suit against NSO Group, securing roughly $168 million in damages (later reduced on review) and, in October 2025, a permanent injunction restraining NSO from targeting WhatsApp infrastructure and users. NSO Group is appealing. A contempt motion asks the same court to enforce its existing injunction with coercive sanctions — potential fines, asset actions, or other penalties — rather than starting a new case. Meta tied the filing to broader policy advocacy, arguing that easing restrictions on NSO would undermine U.S. national security, and noting NSO Group's placement on the U.S. Commerce Department Entity List since November 2021. Citizen Lab researcher John Scott-Railton commented that 'NSO's own actions make the strongest argument for why they should stay on the Entity list.'

The operation echoes a long, well-documented history of NSO Pegasus deployment against journalists, lawyers, and human-rights defenders. Pegasus has historically been delivered via WhatsApp through the 2019 zero-click VOIP exploit (CVE-2019-3568) that NSO used against more than 1,400 devices in a two-week window, and via Apple iMessage zero-click/one-click exploit chains including KISMET, FORCEDENTRY (CVE-2021-30860), FINDMYPWN, PWNYOURHOME, and BLASTPASS (CVE-2023-41064 / CVE-2023-41061). A 2024 Access Now / Citizen Lab investigation documented at least 35 Jordanian journalists, activists, and human-rights lawyers targeted between 2019 and 2023, frequently via malicious WhatsApp and SMS links sent by operators posing as journalists requesting interviews. The June 2026 campaign reuses the social-engineering and external-redirect tradecraft from those operations even though the specific exploit payload behind the 2026 links was not enumerated in public reporting.

No CVE, CVSS, or concrete network IOC was published for the 2026 campaign itself; WhatsApp privately distributed indicators to affected users. Defensive value therefore centers on behavioral detection of spearphishing-link social engineering on messaging platforms, attacker test-account/group creation patterns, redirects to attacker-controlled external sites, and the established Pegasus post-exploitation behaviors on compromised mobile devices.

MITRE ATT&CK techniques used in TL-2026-0728

Defense Evasion

T1070 Indicator Removal; T1628 Hide Artifacts; T1630 Indicator Removal on Host

Command and Control

T1071 Application Layer Protocol; T1437 Application Layer Protocol; T1573 Encrypted Channel

Execution

T1203 Exploitation for Client Execution; T1658 Exploitation for Client Execution

Collection

T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1636 Protected User Data

Credential Access

T1417 Input Capture

Discovery

T1426 System Information Discovery

Initial Access

T1456 Drive-By Compromise; T1566 Phishing; T1660 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in NSO Group Pegasus Spyware

  • WhatsApp / Meta — WhatsApp Messenger
    Vulnerable versions: WhatsApp Android < 2.19.134 (CVE-2019-3568); WhatsApp iOS < 2.19.51; WhatsApp Business Android < 2.19.44
    Fixed in: WhatsApp Android 2.19.134+; WhatsApp iOS 2.19.51+
  • Apple — iOS / iMessage
    Vulnerable versions: iOS < 14.8 (FORCEDENTRY / CVE-2021-30860); iOS <= 16.6 (BLASTPASS / CVE-2023-41064, CVE-2023-41061)
    Fixed in: iOS 14.8; iOS 16.6.1
  • Various — Targeted user populations (journalists, lawyers, activists, officials)
    Vulnerable versions: WhatsApp users approached via spearphishing links and attacker test accounts/groups (2026 campaign)

Remediation for NSO Group Pegasus Spyware

Patches

  • Keep WhatsApp / WhatsApp Business updated (historical fix for CVE-2019-3568 shipped in Android v2.19.134 / iOS v2.19.51).
  • Keep iOS/macOS fully patched; FORCEDENTRY fixed in iOS 14.8 (CVE-2021-30860), BLASTPASS fixed in iOS 16.6.1 (CVE-2023-41064 / CVE-2023-41061).

Immediate actions

  • Treat unsolicited WhatsApp/SMS/email messages containing links — especially those posing as journalists, recruiters, or officials requesting an interview or document review — as potential spyware lures; do not click.
  • Apply the threat indicators WhatsApp distributed to affected users and review whether any household/staff device was approached via the campaign's channels.
  • Enable Apple Lockdown Mode on high-risk iOS devices (journalists, lawyers, activists, executives, officials) — it blocks the known Pegasus iMessage zero-click vectors including BLASTPASS.
  • Force-reboot at-risk mobile devices and rotate credentials/sessions for accounts accessed from them; many Pegasus chains do not survive a reboot but re-infection is common.

Workarounds

  • Disable automatic media download and link previews in messaging apps for at-risk users.
  • Route high-risk communications through hardened, minimal-surface devices and verify sender identity out-of-band before opening any link.

Longer-term hardening

  • Deploy mobile threat defense / MDM with on-device behavioral detection for high-risk user populations.
  • Establish a forensic process aligned to Amnesty International's MVT (Mobile Verification Toolkit) and Pegasus methodology for suspected-target devices.
  • Adopt platform hardening (Lockdown Mode, minimized attack surface, disabling link previews) as policy for at-risk roles.
  • Subscribe to and operationalize commercial-spyware threat indicators from Meta/WhatsApp, Citizen Lab, Amnesty Security Lab, and Apple threat notifications.

CVEs associated with NSO Group Pegasus Spyware

CVE-2019-3568, CVE-2021-30860, CVE-2023-41064, CVE-2023-41061

Weaknesses (CWE) in NSO Group Pegasus Spyware

CWE-787, CWE-122, CWE-1188

Timeline of NSO Group Pegasus Spyware

  • WhatsApp discloses CVE-2019-3568, a zero-click VOIP buffer-overflow used by NSO Pegasus against 1,400+ devices; patched the same week.
  • WhatsApp/Meta files its original civil suit against NSO Group and Q Cyber Technologies over the 2019 WhatsApp exploitation campaign.
  • Citizen Lab publishes FORCEDENTRY (CVE-2021-30860), an NSO iMessage zero-click exploit; Apple patches in iOS 14.8.
  • U.S. Commerce Department adds NSO Group to the Entity List for supplying spyware used to target journalists, activists, and officials.
  • Citizen Lab discloses BLASTPASS (CVE-2023-41064 / CVE-2023-41061), an NSO iMessage zero-click PassKit exploit; Apple patches in iOS 16.6.1.
  • Access Now and Citizen Lab document at least 35 Jordanian journalists, lawyers, and activists targeted with Pegasus (2019-2023) via WhatsApp/SMS malicious links.
  • WhatsApp prevails at trial against NSO Group, with a jury awarding approximately $168 million in damages.
  • A U.S. court enters a permanent injunction barring NSO Group from targeting WhatsApp users and infrastructure; NSO appeals.
  • Meta files a contempt-of-court motion alleging a new NSO spearphishing campaign (malicious links to external sites, attacker test accounts/groups) violated the October 2025 injunction.

Sources cited for NSO Group Pegasus Spyware

Threats related to NSO Group Pegasus Spyware

Detection coverage for TL-2026-0728

As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0728 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats