logo

NSO Group Adds 'MMS Fingerprinting' Zero-Click Attack to Spyware Arsenal

ID: 2a1be7c0-bd0a-533e-ae87-993f8d60615e

STIX ID: report--2a1be7c0-bd0a-533e-ae87-993f8d60615e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A researcher uncovered a previously unreported NSO Group capability called "MMS Fingerprint" that leverages the MMS/WSP Push notification and the subsequent HTTP GET to harvest device User-Agent and header information without user interaction. This zero-click profiling could be used to tailor Pegasus spyware or craft more effective social-engineering attacks; the researcher reproduced the fingerprinting in tests but found no indication it has yet been used in real-world attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.