Friday, April 18, 2025
HomeCyber Security NewsFacebook Filed a Lawsuit Against NSO Group for Hacking WhatsApp Using Zero-Day...

Facebook Filed a Lawsuit Against NSO Group for Hacking WhatsApp Using Zero-Day Bug

Published on

SIEM as a Service

Follow Us on Google News

Facebook lawsuit against Israel based commercial spyware maker NSO group for hacking its WhatsApp messenger by exploiting the zero-day vulnerability and deploy the Pegasus spyware on the targeted user’s device.

Once Pegasus is installed, it begins contacting the operator’s C&C servers to receive and execute operators’ commands, and send back the target’s private data, including passwords, contact lists, calendar events, text messages, and live voice calls from popular mobile messaging apps.

The vulnerability can be tracked as CVE-2019-3568. Which is resides in “WhatsApp VOIP stack allowed remote code execution via a specially crafted series of SRTCP packets sent to a target phone number?

- Advertisement - Google News

In May 2019, WhatsApp experienced a sophisticated cyber attack that exploited the WhatsApp video call system, as a result, 1,400 WhatsApp users believe to be impacted.

WhatsApp detected and blocked the attack soon after learned this incident, after a few months of investigation, now Facebook filed a lawsuit in U.S district count in northern direct of California.

NSO group also known as Q cyber technologies, an Israel based company claims that they develop and sell its spyware only government and law enforcement agencies for tracking criminals and terrorists, but it alleged that their technology also used to target the individual users around the world.

The lawsuit filed by Facebook said that the NSO group violated both U.S. and California laws as well as the WhatsApp Terms & conditions and misuse the WhatsApp server and WhatsApp services to deploy the spyware component in targeted users device by exploiting the Video called feature vulnerability.

NSO group denied this allegation and said “Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies. NSO would not or could not use its technology in its own right to target any person or organization”

But Facebook claims in the lawsuit learned that the attackers used servers and Internet-hosting services to compromise the targeted WhatsApp account were previously associated with NSO Group

Following factual allegation filed by Facebook against NSO Group in a lawsuit:

  • NSO group agreed to the WhatsApp terms
  • NSO group accessed and used WhatsApp’ servers without authorization and infected target users’ devices with malware 
  • NSO group set up computer infrastructure used to infect the target Devices 
  • NSO group unauthorized access of WhatsApp’ servers 
  • NSO group unlawful acts have caused damage and loss to WhatsApp and Facebook. 

According to WhatsApp “This is the first time that an encrypted messaging provider is taking legal action against a private entity that has carried out this type of attack against its users. In our complaint, we explain how NSO carried out this attack, including acknowledgment from an NSO employee that our steps to remediate the attack were effective. ”

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How to Conduct a Cloud Security Assessment

Cloud adoption has transformed organizations' operations but introduces complex security challenges that demand proactive...

U.S DOGE Allegedly Breached – Whistleblower Leaked Most Sensitive Documents

A federal whistleblower has accused the Department of Government Efficiency (DOGE) of orchestrating a...

Building a Security First Culture – Advice from Industry CISOs

In today’s threat landscape, cybersecurity is no longer confined to firewalls and encryption it’s...

Microsoft Prevents Billions of Dollars in Fraud and Scams

Microsoft has reported significant strides in thwarting financial fraud across its ecosystem. From April 2024...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

U.S DOGE Allegedly Breached – Whistleblower Leaked Most Sensitive Documents

A federal whistleblower has accused the Department of Government Efficiency (DOGE) of orchestrating a...

Microsoft Prevents Billions of Dollars in Fraud and Scams

Microsoft has reported significant strides in thwarting financial fraud across its ecosystem. From April 2024...

State Sponsored Hackers now Widely Using ClickFix Attack Technique in Espionage Campaigns

The state-sponsored hackers from North Korea, Iran, and Russia have begunp deploying the ClickFix...