NSO Group used WhatsApp exploits after the messaging app sued the spyware developer, court filing says
Full article893 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The filing also suggests that customers have a minimal role in operating the spyware, in an apparent contradiction of past NSO Group claims.
Listen to this article
0:00
Learn more.
NSO Group developed malware that used WhatsApp to infect victims even after WhatsApp sued the leading spyware vendor over allegations that it violated federal and state anti-hacking laws, according to a court filing by the messaging app and its parent company Meta on Thursday.
It was one of a bevy of revelations and new details found in the filing that expound on how NSO Group operates and the scope of its work. WhatsApp is seeking a summary judgment from the U.S. District Court for the Northern District of California and award of damages.
After detecting NSO Group’s malicious messages in May 2019, WhatsApp made changes to disable the exploit called “Eden,” according to the filing. NSO Group “then developed a new Malware Vector called ‘Erised’ that continued using WhatsApp as an installation vector through at least May 2020 — even after this litigation had been filed — until changes to WhatsApp eventually disabled that Malware Vector, too.”
Those were two of three WhatsApp-centric exploits mentioned in the filing, with the third known as “Heaven” and disabled by WhatsApp in 2018. “NSO admits Eden was responsible for the attacks described in the Complaint” — 1,400 in all, as WhatsApp had claimed and NSO Group admitted, according to the complaint. Additionally, “NSO’s Head of R&D has confirmed that those vectors worked precisely as alleged by Plaintiffs.”
The filing also suggests that NSO Group operates its spyware, contradicting past claims from the Israeli firm.
“NSO’s customers’ role is minimal. The customer only needed to enter the target device’s number and ‘press Install, and Pegasus will install the agent on the device remotely without any engagement,’” the filing reads, quoting from information revealed during the discovery process. “In other words, the customer simply places an order for a target device’s data, and NSO controls every aspect of the data retrieval and delivery process through its design of Pegasus. NSO admits the actual process for installing Pegasus through WhatsApp was ‘a matter for NSO and the system to take care of, not a matter for customers to operate.’”
Gil Lanier, vice president of global communications for NSO Group, said the company “stands behind its previous statements in which we repeatedly detailed that the system is operated solely by our clients and that neither NSO nor its employees have access to the intelligence gathered by the system.” The emailed statement said that the company is “confident that these claims, like many others in the past, will be proven wrong in court, and we look forward to the opportunity to do so.”
The five-year-old lawsuit is one of many filed in an attempt to use courts to battle spyware companies, and one of the most successful so far.
“The evidence unveiled [Thursday] shows exactly how NSO’s operations violated U.S. law and launched their cyber-attacks against journalists, human rights activists and civil society,” a WhatsApp spokesperson said via email. “We are going to continue working to hold NSO accountable and protect our users.”
This story was updated Nov. 15, 2024, to correct the date through which NSO Group used WhatsApp as an installation vector.
More Scoops
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
The company said it spotted a spearphishing campaign linked to the Israeli spyware maker targeting WhatsApp users, despite a court order prohibiting it.
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
WhatsApp releases account feature that looks to combat spyware
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nso-group-used-whatsapp-exploits-after-the-messaging-app-sued-the-spyware-developer-court-filing-says/