NSO Group Adds 'MMS Fingerprinting' Zero-Click Attack to Spyware Arsenal
ID: 2a1be7c0-bd0a-533e-ae87-993f8d60615e
STIX ID: report--2a1be7c0-bd0a-533e-ae87-993f8d60615e
Feed Name: Dark Reading
Threat Score
A researcher uncovered a previously unreported NSO Group capability called "MMS Fingerprint" that leverages the MMS/WSP Push notification and the subsequent HTTP GET to harvest device User-Agent and header information without user interaction. This zero-click profiling could be used to tailor Pegasus spyware or craft more effective social-engineering attacks; the researcher reproduced the fingerprinting in tests but found no indication it has yet been used in real-world attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
