[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_s3PkRPHBPkUutYW6J-Uw9FSAuj09CvkuyDcW5XBYpk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"0cd0e08d-2110-4768-9ae6-b1a436a239ba","nso-group-deploys-pegasus-via-spear-phishing-despite-court-injunction","3e131677-05cd-4ed1-9b91-8570a3a040e0","NSO Group Deploys Pegasus via Spear-Phishing Despite Court Injunction","NSO Group continued operating Pegasus spyware campaigns through spear-phishing attacks that direct users to malicious websites, even while under court injunction. This incident demonstrates how threat actors pivot to social engineering tactics when technical vulnerabilities are patched, and highlights the ongoing challenge of enforcing legal restrictions on sophisticated cyber weapons vendors. The campaign's success depends entirely on user interaction, making security awareness training a critical defense layer against nation-state level threats.","**Immediate actions:**\n- Deploy advanced email filtering to detect and block spear-phishing attempts\n- Implement DNS filtering to block access to known malicious domains\n- Issue security alerts to users about the specific campaign and IOCs\n\n**Long-term improvements:**\n- Establish comprehensive security awareness training focused on spear-phishing recognition\n- Develop incident response procedures specifically for targeted surveillance campaigns\n- Create partnerships with threat intelligence providers for nation-state IOC feeds\n\n**Detection measures:**\n- Monitor network traffic for connections to suspicious domains and IP addresses\n- Implement behavioral analysis to detect unusual user activity patterns\n- Establish legal monitoring processes to track compliance with court injunctions",[12,13,14,15,16],"CIS Control 14 (Security Awareness)","CIS Control 17 (Incident Response)","NIST SP 800-61 (Incident Handling)","NIST SP 800-50 (Security Awareness Training)","GDPR Article 32 (Security Measures)","published","2026-06-09T00:20:19.891365+00:00","2026-06-09T00:20:19.569+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fhackread.com\u002Fwhatsapp-blocked-pegasus-spyware-campaign-nso\u002F","whatsapp-says-it-blocked-pegasus-spyware-campaign-linked-to-nso-56e65a","WhatsApp Says It Blocked Pegasus Spyware Campaign Linked to NSO",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]