> JB knows better than to open files sent to him.
That's not how these NSO spyware attacks work, or used to work – the ones that are now known were zero-click exploits in WhatsApp / iMessage that required no interaction with the message.
https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage...
Of course I'm only guessing that's what was potentially used in this case, but doesn't seem too far fetched.