This filing is a new front in the case WhatsApp opened in October 2019, when it sued NSO Group over an attack that hit 1,400 devices including journalists and human rights defenders (the original lawsuit). Legal observers called WhatsApp's path an uphill battle at the time, and NSO initially argued it deserved foreign official immunity before a US District Judge let the malware case move forward in July 2020.
First-order effects
Alleging US-based servers puts NSO's operations on American soil in court records, undercutting the immunity framing NSO used when it tried to kill the case and giving Meta a stronger jurisdictional hook.
Second-order effects
The claim feeds directly into the discovery pressure already squeezing NSO — a judge later ordered it to hand over its Pegasus code to Meta (the code-disclosure order) and found it liable for spying on the 1,400 users (the liability ruling) — and raises the stakes for the government customers paying $3M–$30M for access, as reporting shows NSO kept targeting WhatsApp users even after being sued (continued targeting after the suit).
Third-order effects
If routing attacks through US infrastructure exposes spyware vendors to US jurisdiction, the industry's model of selling surveillance abroad while operating from American clouds loses its legal shield — pointing toward structural constraints on commercial spyware firms rather than case-by-case lawsuits.
The trend: Commercial spyware vendors are losing the jurisdictional distance their export business model depends on, as platform lawsuits drag their US infrastructure into American courts.
Wow, @WhatsApp just dropped a bunch of hacking group NSO's IPs in their latest filing. Notably, these were servers located in the USA. THREAD https://twitter.com/...
NSO Group, the Israeli software surveillance firm accused of spying on over 1,000 WhatsApp users last year, has used American-based servers to launch its attacks, Facebook/WhatsApp alleges in latest filing. Read more at @CyberScoopNews https://www.cyberscoop.com/...
WhatsApp out with new filings in their case against NSO Group re the famous “missed call” hack. Some new info: in 3 cases, the malicious code delivered through WhatsApp called back to IP 54.93.81.200, which was clearly part of NSO corporate infrastructure https://twitter.com/... …
Ah! Another interesting detail, @WhatsApp engineers observed 723 NSO attacks on users in which phones, once exploited, reached out to NSO-owned servers in California (104.223.76[.]220 - @QuadraNet & 54.93.81[.]200 - @amazon) https://twitter.com/...
The meat of these filings is @WhatsApp's rebuttal of NSO's claim that because they sell to foreign states, they should be immune to prosecution. “Here, NSO is a for-profit commercial company - decidedly not a foreign state https://twitter.com/...
Non-denials like “we don't operate the software for clients” are irrelevant. NSO could be doing the device exploitation, then handing off phones to customers, who then operate the C2 ‘software’. cc @shanvav https://www.cyberscoop.com/... https://twitter.com/...
I heard once that some foreign cyber actors use US servers to muddy the legal waters when it comes to NSA surveillance, since the bar is higher for spying on anyone reasonably believed to be a US person, etc. https://twitter.com/...
Facebook-NSO lawsuit: Hundreds of WhatsApp attacks linked to one IP address. Facebook fights to keep the lawsuit on track after NSO filed a motion to dismiss the case earlier this month. https://www.zdnet.com/... https://twitter.com/...
As @jsrailton tells me, if NSO Group is running these servers, it means it has the ability to collect those logs detailing what its customers are doing. https://twitter.com/...