• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
meta confirms zero click whatsapp spyware attack targeting 90 journalists, activists

Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists

You are here: Home / General Cyber Security News / Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists
February 1, 2025

Meta-owned WhatsApp on Friday said it disrupted a campaign that involved the use of spyware to target journalists and civil society members.

The campaign, which targeted around 90 members, involved the use of spyware from an Israeli company known as Paragon Solutions. The attackers were neutralized in December 2024.

In a statement to The Guardian, the encrypted messaging app said it has reached out to affected users, stating it had “high confidence” that the users were targeted and “possibly compromised.” It’s currently not known who is behind the campaign and for how long it took place.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

The attack chain is said to be zero-click, meaning the deployment of the spyware occurs without requiring any user interaction. It’s suspected to involve the distribution of a specially-crafted PDF file sent to individuals who were added to group chats on WhatsApp.

The company also revealed that it had sent Paragon a “cease and desist” letter and that it was considering other options. The development marks the first time the company has been linked to cases where its technology has been misused.

Like NSO Group, Paragon is the maker of surveillance software called Graphite that’s offered to government clients in order to combat digital threats. It was acquired by a U.S.-based investment group AE Industrial Partners in December in a deal worth $500 million.

On its barebones website, the company claims it provides customers with “ethically based tools” to “disrupt intractable threats,” as well as offer “cyber and forensic capabilities to locate and analyze digital data.”

In late 2022, it came to light that Graphite was used by the U.S. Drug Enforcement Administration (DEA) for counternarcotics operations. Last year, the Center for Democracy and Technology (CDT) called on the Department of Homeland Security to release details about its $2 million contract with Paragon.

Cybersecurity

News of the campaign comes weeks after a judge in California ruled in WhatsApp’s favor in a landmark case against NSO Group for using its infrastructure to deliver the Pegasus spyware to 1,400 devices in May 2019.

Meta’s disclosure also coincided with the arrest of former Polish Justice Minister Zbigniew Ziobro over allegations that he sanctioned the use of Pegasus spyware to surveil opposition leaders and oversaw cases where the technology was used.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «malvertising scam uses fake google ads to hijack microsoft advertising Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts
Next Post: BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key beyondtrust zero day breach exposes 17 saas customers via compromised api»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.