Israeli NSO Group Suspected of “MMS Fingerprint” Attack on WhatsApp
ID: adb5e207-5674-5965-9d9f-e9bd60e31194
STIX ID: report--adb5e207-5674-5965-9d9f-e9bd60e31194
Feed Name: HackRead
Enea reports that NSO Group likely used a novel "MMS Fingerprint" technique—sending binary MMS/WSP Push notifications that trigger automatic MM1_retrieve HTTP GETs—to leak device UserAgent and x-wap-profile fields without user interaction; this information can enable tailored exploits and has been linked to Pegasus spyware targeting journalists, activists, and officials. The technique was demonstrated against sample SIMs and captured via packet traces; mitigations include disabling MMS auto-retrieval where possible and filtering/blocking binary MMS notifications to attacker-controlled URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
