logo

Israeli NSO Group Suspected of “MMS Fingerprint” Attack on WhatsApp

ID: adb5e207-5674-5965-9d9f-e9bd60e31194

STIX ID: report--adb5e207-5674-5965-9d9f-e9bd60e31194

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-02-16

Date Updated: 2026-04-22

Author: Waqas

...
...

Enea reports that NSO Group likely used a novel "MMS Fingerprint" technique—sending binary MMS/WSP Push notifications that trigger automatic MM1_retrieve HTTP GETs—to leak device UserAgent and x-wap-profile fields without user interaction; this information can enable tailored exploits and has been linked to Pegasus spyware targeting journalists, activists, and officials. The technique was demonstrated against sample SIMs and captured via packet traces; mitigations include disabling MMS auto-retrieval where possible and filtering/blocking binary MMS notifications to attacker-controlled URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.