OTHER

Five Essential Insights from the WhatsApp vs. NSO Group Spyware Lawsuit

On Tuesday, WhatsApp secured a major legal victory against NSO Group, with a jury ordering the infamous spyware company to pay over $167 million in damages to the Meta-owned platform.

This decision concluded a protracted legal battle that started in October 2019, when WhatsApp accused NSO Group of infiltrating over 1,400 user accounts by exploiting a vulnerability within the app’s audio-calling feature.

The jury’s ruling came after a week-long trial featuring testimonies from pivotal figures, including NSO Group’s CEO Yaron Shohat and WhatsApp employees who investigated the breach.

Before the trial, numerous significant revelations surfaced, including NSO Group’s termination of contracts with 10 government clients for misusing its Pegasus spyware, identifying 1,223 victims of the spyware campaign, and revealing three client nations: Mexico, Saudi Arabia, and Uzbekistan.

TechCrunch has gone through the trial transcripts, spotlighting the most compelling facts and discoveries that emerged. We will keep this post updated as more information becomes available from the extensive collection of over 1,000 pages.

How the WhatsApp Attack Was Executed

The zero-click attack, requiring no action from victims, “operated by placing a deceptive WhatsApp call to the target,” explained WhatsApp’s attorney Antonio Perez during the trial. He detailed that NSO Group created a system referred to as the “WhatsApp Installation Server,” which aimed to spread harmful messages through WhatsApp’s infrastructure, imitating legitimate communications.

“Once received, these messages would prompt the user’s device to connect to an external server to download the Pegasus spyware, with only the phone number needed for the process,” Perez noted.

Tamir Gazneli, NSO Group’s VP of research and development, testified that “any zero-click solution is a major achievement for Pegasus.”

NSO Group Acknowledges Targeting an American Phone Number as a Test for the FBI

Contact Us

Do you have additional information about NSO Group or other spyware firms? From a personal device and secure network, you can confidentially reach out to Lorenzo Franceschi-Bicchierai on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

For years, NSO Group has claimed that its spyware cannot target American phone numbers, particularly those with the +1 country code.

In 2022, The New York Times first reported that the company indeed “attacked” a U.S. number, but this was part of a test for the FBI.

NSO Group’s attorney Joe Akrotirianakis confirmed this, stating that the “one exception” to the ban on targeting +1 numbers “was a specially configured version of Pegasus used for demonstrations to potential U.S. government clients.”

The FBI allegedly chose not to proceed with Pegasus after its test.

How NSO Group’s Government Clients Utilize Pegasus

According to NSO’s CEO Shohat, the user interface of Pegasus for government clients does not provide options for selecting specific hacking methods or techniques against designated targets, “because customers are indifferent to the vector, as long as they gather the necessary intelligence.”

Essentially, it is the Pegasus system in the background that determines which hacking technology—known as an exploit—should be deployed for each target.

Co-location of NSO Group’s Headquarters with Apple

In an unexpected turn, NSO Group’s headquarters in Herzliya, a suburb of Tel Aviv, share a building with Apple, whose iPhone users are frequently targetted by NSO’s Pegasus spyware. Shohat noted that NSO occupies the top five floors while Apple occupies the remainder of the 14-floor structure.

It is significant that NSO Group’s headquarters are publicly listed; many spyware developers, like the now-defunct Barcelona-based Variston, operated from co-working spaces while misrepresenting their locations on official sites.

NSO Group Acknowledges Continued Targeting of WhatsApp Users Post-Lawsuit

Following the spyware attack, WhatsApp filed a lawsuit against NSO Group in November 2019. Nevertheless, despite the ongoing legal conflict, the spyware company continued targeting users of the messaging application, as stated by NSO Group’s VP of research and development Tamir Gazneli.

Gazneli disclosed that “Erised,” the code name for one version of the WhatsApp zero-click vector, remained operational from late 2019 until May 2020. Other versions included “Eden” and “Heaven,” collectively known as “Hummingbird.”