PA Images
The attack was carried out by an advanced cyber actor.

Hackers installed malware on phones and other devices by exploiting a weakness in the messaging app.

WhatApp says the attack affected a “select number” of users, and was carried out by “an advanced cyber actor”.

NSO Group, an Israeli security group, carried out the attack, according to the Financial Times.

Facebook told uders to update their apps as an added security measure.

A software update was issued on Friday.

The attack is thought to involve a weakness in the voice calling mode.

The surveillance software was installed even if the call was not picked up.

 

‘Cyber Arms Dealer’

In a statement, WhatsApp said:

“The attack has all the hallmarks of a private company reportedly that works with government to deliver spyware that takes over the functions of mobile phone operating systems.”

“We have briefed a number of human rights organisations to the information we can and to work with them to notify civil society.”

The NSO Group is an Israeli “cyber arms dealer”.

The company is partially owned by London equity firm Novalpina Capital.

NSO’s flagship software is ‘Pegasus’, which collects data from target devices via microphones, phone cameras and location data.

In a statement, the group said:

“NSO’s technology is licensed to authorised government agencies for the sole purpose of fighting crime and terror.”

The NSO Group told the FT:

“Under no circumstances should the NSO be involved in the operating or identifying of targets of its technology”.

“This is solely operated by intelligence and law enforcement agencies.”

 

‘Not something to worry about’

It is said that the suspected breach was highly targeted.

And WhatsApp have not yet confirmed how many users have been affected by the attack.

Scott Storey, a senior lecturer in cyber security at Sheffield Hallam University, believes most WhatsApp users were not affected however. That’s because this appears to be governments targeting specific people, mainly human rights campaigners.
“For the average end user, it’s not something to really worry about,” he said, adding that WhatsApp found the vulnerability and quickly fixed it. “This isn’t someone trying to steal private messages or personal details.”