NSO Group made a site appearing to belong to Facebook's security team to entice targets into installing malware; FB got ownership of the domain to shut it down
Joseph Cox / VICE : Tweets: @lorenzofb , @dangoodin001 , and @jason_koebler Tweets: Hangry Lorenzo / @lorenzofb : NSO Group impersonated Facebook in an attempt to help clients hack targets. .@josephfcox found a web domain that looked like a Facebook site and was used for phishing targets to instal NSO's spyware. https://www.vice.com/... Dan Goodin / @dangoodin001 : When I get subscribed to a list without permission I respond to the sender (& any other email addresses I can find for the company) and demand I be removed. Sometimes I get a reply that says I can just use the unsubscribe link. No, I can't and here's why: https://www.vice.com/... https://twitter.com/... Jason Koebler / @jason_koebler : scoop: NSO caught impersonating Facebook, using Amazon servers to deliver malware https://www.vice.com/...
Context & Ripple Effects
NSO Group has spent 2020 defending its reputation on two fronts: the exposure of its unprotected Fleming contact-tracing system and reporting on hundreds of millions in Gulf-state Pegasus sales. Now VICE documents the offensive side of that business — a fake Facebook security-team website used to lure targets into installing NSO spyware, which Facebook neutralized by taking over the domain itself.
The impersonation cuts both ways given the history between the two companies: NSO's CEO has already claimed in court filings that Facebook approached NSO in 2017 about buying parts of Pegasus for Onavo monitoring. A platform whose brand is being weaponized by a vendor it once negotiated with now has direct evidence for its abuse case.
First-order effects
- Targets who received the phishing link faced a working NSO infection attempt dressed up as official Facebook security communication; Facebook's seizure of the domain immediately kills that delivery route and hands the company forensic access to the lure site.
Second-order effects
- The government clients behind NSO's Gulf-state deals lose a proven pretext — a trusted brand's security alert is precisely what makes targets click — forcing reliance on costlier or noisier delivery methods, while the discovery hands Facebook ammunition in its litigation posture toward NSO.
Third-order effects
- If platforms keep seizing attacker infrastructure rather than just filing takedowns, commercial spyware vendors face a structural problem: their core technique — impersonating trusted brands — puts them in direct conflict with the few companies rich enough to fight back at the domain level, pushing the industry toward either more deniable front companies or regulatory scrutiny of who buys Pegasus and why.
The trend: Commercial spyware operators and major platforms are escalating from legal disputes into direct infrastructure warfare, with each documented impersonation giving platforms both the motive and the means to dismantle vendor operations piece by piece.