Notorious NSO Group exploits flaw to send malicious messages and more

Two people texting on smartphones
(Image credit: Pixabay)

Notorious Israeli commercial spyware company NSO Group was reportedly offering a way to exfiltrate sensitive mobile phone data unlike anything ever seen before, experts have revealed. 

A new report from telecom security specialists Enea discovered the method while recently sifting through the documents filed during the court case between WhatsApp and NSO Group.

According to ENEA, in late 2019, WhatsApp committed into evidence a copy of a contract between an NSO Group reseller, and the telecom regulator of Ghana. In the contract, one of the features and capabilities NSO Group offered was called “MMS Fingerprint”.

Blocking malicious MMS messages

This feature, as it later turned out, was exploiting a vulnerability in both Android and iOS (but also in BlackBerry devices, apparently) to exfiltrate some sensitive data from the device. 

After a bit of digging, ENEA managed to recreate the flaw, and then explained how it worked. Allegedly, the attacker could create a unique, malicious MMS message, which the victim didn’t even need to open (or otherwise interact with). That message would trigger the device to return two unique pieces of information: the MMS UserAgent, and the x-wap-profile.

The former is a string that usually identifies the operating system and the device of the victim, while the latter points to a UAProf (User Agent Profile), that describes the capabilities of the target device. 

This information, ENEA argues, could be used to profile the victim and prepare for more concrete attacks: “Both of these can be very useful for malicious actors. Attackers could use this information to exploit specific vulnerabilities or tailor malicious payloads (such as the Pegasus exploit) to the recipient device type. Or it could be used to help craft phishing campaigns against the human using the device more effectively,” the researchers explained in the report.

While being able to steal data without victim interaction sounds ominous, the victims aren’t utterly helpless, ENEA adds. Mobile subscribers could disable MMS auto-retrieval on their handset, which would prevent the malicious messages from reaching their devices. Also, most mobile operators today filter these kinds of messages from being sent in the first place.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Trojan
WhatsApp patches security flaw which let hackers install spyware
WhatsApp China VPN
Paragon spyware campaign targeting journalists disrupted by WhatsApp
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand