/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

NSO Group made a site appearing to belong to Facebook's security team to entice targets into installing malware; FB got ownership of the domain to shut it down

Joseph Cox / VICE : Tweets: @lorenzofb , @dangoodin001 , and @jason_koebler Tweets: Hangry Lorenzo / @lorenzofb : NSO Group impersonated Facebook in an attempt to help clients hack targets. .@josephfcox found a web domain that looked like a Facebook site and was used for phishing targets to instal NSO's spyware. https://www.vice.com/... Dan Goodin / @dangoodin001 : When I get subscribed to a list without permission I respond to the sender (& any other email addresses I can find for the company) and demand I be removed. Sometimes I get a reply that says I can just use the unsubscribe link. No, I can't and here's why: https://www.vice.com/... https://twitter.com/... Jason Koebler / @jason_koebler : scoop: NSO caught impersonating Facebook, using Amazon servers to deliver malware https://www.vice.com/...

VICE Joseph Cox

Context & Ripple Effects

NSO Group has spent 2020 defending its reputation on two fronts: the exposure of its unprotected Fleming contact-tracing system and reporting on hundreds of millions in Gulf-state Pegasus sales. Now VICE documents the offensive side of that business — a fake Facebook security-team website used to lure targets into installing NSO spyware, which Facebook neutralized by taking over the domain itself.

The impersonation cuts both ways given the history between the two companies: NSO's CEO has already claimed in court filings that Facebook approached NSO in 2017 about buying parts of Pegasus for Onavo monitoring. A platform whose brand is being weaponized by a vendor it once negotiated with now has direct evidence for its abuse case.

First-order effects

  • Targets who received the phishing link faced a working NSO infection attempt dressed up as official Facebook security communication; Facebook's seizure of the domain immediately kills that delivery route and hands the company forensic access to the lure site.

Second-order effects

  • The government clients behind NSO's Gulf-state deals lose a proven pretext — a trusted brand's security alert is precisely what makes targets click — forcing reliance on costlier or noisier delivery methods, while the discovery hands Facebook ammunition in its litigation posture toward NSO.

Third-order effects

  • If platforms keep seizing attacker infrastructure rather than just filing takedowns, commercial spyware vendors face a structural problem: their core technique — impersonating trusted brands — puts them in direct conflict with the few companies rich enough to fight back at the domain level, pushing the industry toward either more deniable front companies or regulatory scrutiny of who buys Pegasus and why.

The trend: Commercial spyware operators and major platforms are escalating from legal disputes into direct infrastructure warfare, with each documented impersonation giving platforms both the motive and the means to dismantle vendor operations piece by piece.

Discussion

  • @lorenzofb Hangry Lorenzo on x
    NSO Group impersonated Facebook in an attempt to help clients hack targets. .@josephfcox found a web domain that looked like a Facebook site and was used for phishing targets to instal NSO's spyware. https://www.vice.com/...
  • @dangoodin001 Dan Goodin on x
    When I get subscribed to a list without permission I respond to the sender (& any other email addresses I can find for the company) and demand I be removed. Sometimes I get a reply that says I can just use the unsubscribe link. No, I can't and here's why: https://www.vice.com/...…
  • @jason_koebler Jason Koebler on x
    scoop: NSO caught impersonating Facebook, using Amazon servers to deliver malware https://www.vice.com/...