HT TECH wants to start sending you push notifications. Click allow to subscribe

Breaking down NSO Group’s Pegasus spyware, WhatsApp’s video-calling vulnerability

WhatsApp claims Israel-based surveillance firm NSO Group exploited vulnerability in video-calling feature to hack users’ accounts.

By: KUL BHUSHAN
Updated on: Aug 20 2022, 17:40 IST
WhatsApp sues Israel’s NSO for allegedly helping spies hack phones (Pixabay)
WhatsApp sues Israel’s NSO for allegedly helping spies hack phones (Pixabay)

WhatsApp on Thursday sued Israel-based surveillance firm NSO Group for allegedly hacking the messaging platform to spy on about 1,400 users. The targeted users included activists, journalists, and senior government officials among others. WhatsApp alleged that NSO Group exploited a vulnerability in its video-calling feature to conduct the cyber attacks.

WhatsApp and its users have long been targeted by hackers around the world despite the instant messaging app boasts of highly secure end-to-end encryption. From GIFs to spoofing user identity, hackers have adopted innovative ways to hack users' accounts. In the case of the latest NSO Group, WhatsApp traced the cyberattack to a May 2019 incident where the vulnerability allowed hackers to remotely install spyware. Malicious actors used 'Pegasus', a popular spying tool offered by the Israel firm.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
34% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹98,799₹149,999
Buy now
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

What is Pegasus?

Also read: Looking for a smartphone? To check mobile finder click here.

Pegasus is believed to be one of the most sophisticated spyware in the world. The spyware can hack both iOS and Android devices by targeting vulnerabilities in the operating systems. It is capable of running in the background without the targeted user ever knowing about the hack. Once the spyware is installed on a device, it accesses critical and private data of users such as contacts, messages, passwords, and even live voice calls. It can also remotely switch on the affected device's camera and microphone.

"Other vectors used in prior cases of NSO targeting include tricking targets into clicking on a link using social engineering. For example, in 2017, the wife of a murdered Mexican journalist was sent alarming text messages concerning her husband's murder, designed to trick her into clicking on a link and infecting her phone with the Pegasus spyware," wrote Citizen Lab in a blog post.

"Pegasus and its variants (collectively, "Pegasus") were designed to be remotely installed and enable the remote access and control of information—including calls, messages, and location—on mobile devices using the Android, iOS, and BlackBerry operating systems," said WhatsApp in its lawsuit against the NSO Group.

"According to media reports and NSO documents, Defendants [NSO Group] claimed that Pegasus could be surreptitiously installed on a victim's phone without the victim taking any action, such as clicking a link or opening a message (known as remote installation). Defendants promoted that Pegasus's remote installation feature facilitated infecting victims' phones without using spearphishing messages that could be detected and reported by the victims," it added.

How suspected infection attempts were made by hackers (Citizen Labs)
How suspected infection attempts were made by hackers (Citizen Labs)

Hacking via video calling

The exploit, now fixed, allowed malicious actors to hack WhatsApp by just making a video call. The targeted user didn't even need to receive the video call to be infected. Facebook later confirmed that WhatsApp vulnerability occurred due to a rather common bug known as buffer overflow.

Buffer overflow essentially refers to an anomaly wherein data overflows to other parts of memory and overwrites adjacent memory location. Hackers can use the exploit to inject malicious code and acquire access to a device.

"A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number," Facebook said after fixing the exploit.

"The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15," it added.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 31 Oct, 12:17 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
24% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,710₹12,700
Buy now
18% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹93,648₹113,798
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Zephyrus G14 GA402NU N2023WS Laptop
  • Eclipse Gray
  • 16 GB RAM
  • 1 TB SSD
₹144,990₹201,990
Buy now
29% OFF
Asus VivoBook Pro 15 OLED M6500IH L1701WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹58,990₹82,990
Buy now
22% OFF
Asus ROG Strix G15 G512LV AZ225T Laptop
  • Glacier Blue
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now