Pegasus: How NSO Group exploited 0-day vulnerabilities in XhatsApp
Articles by the same author:
1
3
On November 14, 2024, a California court published legal documents related to the lawsuit filed in May 2019 by WhatsApp against NSO Group, the Israeli company behind the Pegasus spyware. The documents reveal that NSO Group exploited 0-day vulnerabilities in the messaging app’s code to spy on its users, even after WhatsApp’s lawsuit was filed.
The released documents include depositions from NSO Group employees, internal records, and messages exchanged between staff members. They detail how the Israeli company “developed these exploits by extracting and decompiling WhatsApp’s code, conducting reverse engineering on WhatsApp.”
NSO Group admitted before the U.S. court to exploiting these vulnerabilities to install its spyware on “tens of thousands of devices.” The published documents also prove that NSO Group often played an active role in installing Pegasus on infected devices, contrary to the company’s long-standing claims.
In July 2021, an international journalistic investigation uncovered widespread illegal use of the spyware. Government entities used it to spy on political figures, activists, journalists, and business leaders.