Israeli cyber-espionage firm NSO Group must give WhatsApp access to source code for its Pegasus spyware, a US district court judge ruled.
NSO has earned a dubious reputation after media organizations and nonprofits like the University of Toronto’s Citizen Lab repeatedly flagged Pegasus’s use by authoritarian governments to attack journalists, activists, and others. In 2019, WhatsApp owner Facebook (now Meta) sued NSO after concluding that the firm had exploited a vulnerability in the chat app to infect over 1,400 phones with malware.
According to TechRadar, US District Court Judge Phyllis Hamilton ruled that WhatsApp was entitled to “information concerning the full functionality of the relevant spyware,” granting it access to source code for Pegasus and other malware from April 2018 to May 2020. The order allows NSO Group to keep the identities of clients and other data like server architectures confidential.
A spokesperson for WhatsApp told the Guardian the ruling is an “important milestone in our long-running goal of protecting WhatsApp users against unlawful attacks,” while NSO declined to comment. NSO has long insisted government clients are responsible for any abuse of its products.
Citizen Lab senior research fellow Bill Marczak challenged that argument at SANS Cyber Threat Intelligence Summit earlier this year, telling attendees mercenary spyware vendors do not “sell a product and forget it” but offer “ongoing support, ongoing maintenance, without which the product is essentially useless.”
