Judge rules that NSO cannot continue to install spyware via WhatsApp pending appeal

A California federal judge on Friday declined to stay an order preventing the NSO Group from using WhatsApp infrastructure to mount spyware attacks.

NSO Group had sought to stay the order pending a decision on its appeal in the case, which centers on allegations that it targeted 1,400 WhatsApp users with its powerful zero-click Pegasus spyware in 2019.

The spyware manufacturer has said that the permanent injunction will cause “catastrophic” damage to its business and that it will “suffer irreparable, potentially existential injuries” as a result.

“The court does not find that defendants have made a strong showing of likelihood

of success on the merits of their arguments regarding liability,” the opinion says. 

“Even based only on the limited discovery provided by defendants, the undisputed evidence showed that NSO went far beyond their authorized use of Whatsapp by reverse-engineering the application to design a spyware vector which allowed NSO’s clients to surveil Whatsapp’s users and obtain data from its servers.” 

The judge did issue a limited administrative stay of up to 45 days to allow NSO Group to ask an appeals court to weigh in.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

 

Total
0
Shares
Previous Post

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

Next Post

Cyber spies use fake New Year concert invites to target Russian military

Related Posts

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

Certain motherboard models from vendors like ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by a security vulnerability that leaves them susceptible to early-boot direct memory access (DMA) attacks across architectures that implement a Unified Extensible Firmware Interface (UEFI) and input–output memory management unit (IOMMU). UEFI and IOMMU are designed to enforce a security
Read More

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to execute arbitrary system commands on the underlying host. The vulnerability, tracked as CVE-2025-68668, is rated 9.9 on the CVSS scoring system. It has been described as a case of a protection mechanism failure. It affects n8n versions from
Read More

Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access

Cybersecurity researchers have disclosed that a critical security flaw impacting ICTBroadcast, an autodialer software from ICT Innovations, has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2025-2611 (CVSS score: 9.3), relates to improper input validation that can result in unauthenticated remote code execution due to the fact that the call center
Read More