Digital forensics researchers uncovered a zero-click exploit chain targeting a popular messaging app, used to plant spyware on the phones of journalists and civil society figures.
The exploit required no interaction from victims — a specially crafted message silently triggered code execution, installing surveillance tooling capable of harvesting messages, activating microphones and tracking locations.
The app's developers released emergency patches within days of receiving the technical report, and notified a subset of users believed to have been targeted.
Attribution remains contested, but the tradecraft aligns with commercial spyware frameworks sold to government clients — an industry facing growing sanctions and export restrictions.
