WhatsApp Blocks Spyware Phishing Attacks
Coverage from BleepingComputer, The Record, and others

WhatsApp has reported disrupting spyware-related campaigns that targeted users through malicious links, fake accounts, and a counterfeit version of the app.
The company alleges that NSO Group-linked activity violated a permanent court injunction and is pursuing legal action, while separately notifying about 200 users exposed to Italian-made government-grade spyware. The incidents show that attackers can target users through social engineering and software impersonation even when messaging content remains protected by end-to-end encryption.
The update sharpens the threat model by adding that WhatsApp’s latest disruption involved fake accounts, test groups, and malicious links leading off-platform, while also clarifying the legal claim against NSO as an alleged injunction violation. It also reframes the separate spyware warning around a counterfeit app carrying Italian-made government-grade spyware.
The story has broadened from NSO-linked phishing disruption to a more concrete enforcement and spyware-distribution problem, with Meta now seeking court action over a permanent injunction and a separate counterfeit app incident exposing users to government-grade spyware. The framing also shifts from exploit-based targeting to user deception and unofficial app installation as the key delivery mechanisms.
