{"id":25741,"date":"2025-02-03T08:10:07","date_gmt":"2025-02-03T16:10:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2025\/02\/03\/news-19464\/"},"modified":"2025-02-03T08:10:07","modified_gmt":"2025-02-03T16:10:07","slug":"news-19464","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2025\/02\/03\/news-19464\/","title":{"rendered":"WhatsApp says Paragon is spying on specific users"},"content":{"rendered":"\n<p>WhatsApp has accused the professional spyware company Paragon of spying on a select group of users.<\/p>\n<p>WhatsApp, the Meta-owned, end-to-end encrypted messaging platform, said it has reliable information that nearly 100 journalists and other \u201cmembers of civil society\u201d were targets of a spyware campaign conducted by the Israeli spyware company.<\/p>\n<p>&#8220;Members of civil society&#8221; usually refers to individuals and organizations that operate independently from government and business sectors, often those advocating for public interests, influencing policy, or holding governments accountable.<\/p>\n<p>In a statement, a WhatsApp spokesperson said:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cThis is the latest example of why spyware companies must be held accountable for their unlawful actions. WhatsApp will continue to protect people\u2019s ability to communicate privately\u201d<\/p>\n<\/blockquote>\n<p>Many such targets use WhatsApp because they rely on the end-to-end encryption (E2EE) that it offers by default to safeguard communications, protect sources, and shield sensitive information from prying eyes.<\/p>\n<p>The targets were spread over two dozen countries, including several in Europe.\u00a0WhatsApp notified the possibly affected accounts through its own app. The platform has the ability notify users about sensitive matters directly via a WhatsApp chat. In such a case, the chat will include a system message at the top of the chat that verifies that it originates from the official account of WhatsApp Support, and there will be a blue checkmark next to WhatsApp Support at the top of the chat.<\/p>\n<p>A spokesperson stated that WhatsApp was able to identify and block the attack vector which Paragon used in these attacks. <a href=\"https:\/\/techcrunch.com\/2025\/01\/31\/whatsapp-says-it-disrupted-a-hacking-campaign-targeting-journalists-with-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Reportedly<\/a>, the hacking campaign used malicious PDFs sent via WhatsApp groups to compromise targets. The attack apparently required no action from the target, a so-called zero-click attack.<\/p>\n<p>Researchers have often compared Paragon\u2019s Graphite spyware to the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/pegasus-spyware-creator-ordered-to-reveal-code-used-to-spy-on-whatsapp-users\">Pegasus spyware<\/a>, a deeply invasive tool developed by a company called NSO that WhatsApp has been fighting in court since 2019. But up until now, Paragon was able to keep a low profile. This is the first time that Paragon has been publicly linked to a hacking campaign that allegedly targeted journalists and members of civil society.<\/p>\n<p>WhatsApp has sent Paragon Solutions a cease-and-desist letter following the series of attempted attacks. Meta also notified Canadian privacy watchdog Citizen Lab. Citizen Lab\u2019s researcher John Scott-Railton says they observed this campaign and have started an investigation.<\/p>\n<p>The attacks reportedly took place in December 2024. If you are a potential target and you received a suspicious PDF you can reach out to <a href=\"https:\/\/citizenlab.ca\/about\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Citizen Lab<\/a> or the non-profit digital security helpline <a href=\"https:\/\/www.accessnow.org\/help\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">A<\/a><a href=\"https:\/\/www.accessnow.org\/help\/\">ccessNow<\/a>.<\/p>\n<p>If you received a WhatsApp notification about the attack, you can contact WhatsApp Support in-app by&nbsp;<a href=\"https:\/\/api.whatsapp.com\/support\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">clicking here<\/a>.<\/p>\n<hr class=\"wp-block-separator alignfull has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don\u2019t just report on phone security\u2014we provide it<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/ios\">downloading Malwarebytes for iOS<\/a>, and <a href=\"https:\/\/www.malwarebytes.com\/android\">Malwarebytes for Android<\/a> today.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2025\/02\/whatsapp-says-paragon-is-spying-on-specific-users\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> WhatsApp has accused professional spyware company Paragon of spying on a select group of users. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[24960,32,32374,11940,5897,10440],"class_list":["post-25741","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-citizen-lab","tag-news","tag-paragon","tag-pegasus","tag-privacy","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25741"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25741\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}