Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios Kouloglou

Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against (TL-2026-1098), also tracked as PWNYOURHOME Campaign, is a high-severity malware campaign, first published 2026-07-03. It has no confirmed attribution, affects Apple iOS / iPadOS (HomeKit and MessagesBlastDoorService components), maps to 30 MITRE ATT&CK techniques (T1404, T1406, T1409), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1098

Threat ID
TL-2026-1098
Also known as
PWNYOURHOME Campaign, Espionage Against the European Parliament, Kouloglou Pegasus Case
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-03
Last reviewed
2026-07-03
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, legislative, civil society, news - media, non-profit organisation
Target regions
Europe, European Union, greece, belgium
Detection rules
9
Indicators of compromise
23

Malware and tooling in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

Malware and tooling: Chrysaor

Citizen Lab forensic analysis confirmed NSO Group's Pegasus spyware infected the iPhone of Stelios Kouloglou, a substitute member of the European Parliament's PEGA Committee investigating spyware abuse, on October 21, 2022 and again on March 6-7, 2023, via the zero-click PWNYOURHOME exploit chain (HomeKit -> iMessage BlastDoor -> mediaserverd). The operator has not been attributed to a specific government, but the attacker-controlled email rauharepo888@gmail.com links the case to a separate NSO customer campaign against exiled Russian and Belarusian journalists disclosed in May 2024.

How Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against works

The Citizen Lab, in a report published July 2-3, 2026, disclosed forensic evidence that the iPhone of Stelios Kouloglou -- a Greek journalist and former Member of the European Parliament who served as a substitute member of the PEGA Committee (the European Parliament's Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, active March 24, 2022 to July 18, 2023) -- was infected twice with NSO Group's Pegasus spyware. The first infection occurred on or around October 21, 2022 at approximately 10:16 UTC, ten days before Kouloglou was to join a PEGA delegation trip to Greece and Cyprus and while he was hospitalized for elective surgery. The second infection occurred between March 6 09:49 UTC and March 7 07:30 UTC 2023, coinciding with PEGA committee deliberations in Brussels on the panel's final report. Both infections were assessed by Citizen Lab with high confidence and are believed to use the same exploit chain. This is the first publicly documented case of a sitting PEGA Committee member being confirmed as a Pegasus victim during active service on the inquiry.

Both infections were delivered via PWNYOURHOME, a novel two-phase zero-click exploit chain first documented by Citizen Lab in its April 2023 'Triple Threat' report alongside two related chains (FINDMYPWN and LATENTIMAGE) used by NSO Group against iOS 15 and early iOS 16 in 2022. PWNYOURHOME's first phase abuses Apple's HomeKit smart-home framework: the attacker performs a HomeKit-linked lookup of an attacker-controlled Apple ID/email address (rauharepo888@gmail.com in this case), delivering a crafted NSKeyedArchiver-serialized message that is processed by the HomeKit daemon (homed) without adequate origin validation. This first stage crashes/manipulates the HomeKit daemon and stages a second payload delivered through iMessage, where a maliciously crafted PNG image is processed by the MessagesBlastDoorService sandbox, causing it to crash and executing attacker code. The exploit chain culminates in code execution being handed off to the mediaserverd process, from which the Pegasus implant is deployed with no visible interaction required from the victim. Apple mitigated the HomeKit phase of the attack in iOS 16.3.1 (released February 13, 2023) by adding validation that declines to decode HomeKit messages arriving from implausible sources; the MessagesBlastDoorService component was likely hardened earlier, around iOS 16.1. Both of Kouloglou's infections occurred while his device was running the outdated iOS 15.5 (build 19F77), which remained vulnerable to the full PWNYOURHOME chain. Apple's Lockdown Mode, introduced in iOS 16, is documented by Citizen Lab to block PWNYOURHOME and surface real-time attack notifications, though researchers suspect NSO Group has worked to fingerprint and evade Lockdown Mode's notification behavior.

Citizen Lab's investigation, governed by University of Toronto Research Ethics Board protocols, was unable to attribute the intrusions to a specific government or confirm which NSO Group customer conducted the operation. Investigators explicitly found no evidence implicating the Greek government or that Greece is an NSO Group customer, but noted that infection activity appears to intersect at least two European jurisdictions (Greece and Belgium), consistent with an NSO customer holding multi-jurisdiction licensing or a customer operating extraterritorially against a target traveling between EU institutions. The strongest attribution lead is infrastructural: the same rauharepo888@gmail.com HomeKit-lookup address used against Kouloglou also appears (as 'Email 1') in a May 2024 joint Citizen Lab/Access Now report, 'By Whose Authority?', which documented Pegasus infections of at least seven Russian- and Belarusian-speaking journalists and civil society figures exiled in Europe, including Latvia-based Russian journalist Maria Epifanova (infected August 2020, the earliest known Pegasus use against Russian civil society) and Poland-based Belarusian journalist Natalya Radina. Because Citizen Lab assesses that these HomeKit delivery email addresses are operator-specific and not shared/resold between NSO customers, the shared address strongly suggests the same Pegasus operator/customer targeted both the Russian/Belarusian civil-society network and a sitting member of the EU body created specifically to investigate spyware abuse.

Apple sent Kouloglou three separate state-sponsored-attacker threat notifications (March 2, 2023; August 29, 2023; and April 10, 2024), none of which he recalls seeing or acting on -- illustrating a recurring gap between vendor threat notifications and real-world remediation among high-risk targets. The case adds to a long pattern of Pegasus and other commercial spyware (Predator/Intellexa, Candiru) being used against PEGA Committee members and associated European political figures, including Carles Puigdemont, Diana Riba, and Jordi Solé (Catalan MEPs targeted 2019-2020, 'CatalanGate'), Nikos Androulakis (Predator), Elena Yoncheva (Pegasus, October 2023), Nathalie Loiseau (Pegasus, February 2024), Daniel Freund (Candiru, May 2024), and Greek journalist Thanasis Koukakis (Intellexa Predator, March 2022). Citizen Lab founder Ron Deibert characterized the likely motive as an attempt to breach parliamentary privilege and monitor the committee's investigation into spyware abuse itself -- a direct challenge to EU efforts at regulatory accountability for the commercial spyware industry. Because Kouloglou's infections occurred while he was interacting with confidential PEGA committee materials, deliberations, and travel logistics, the attacker(s) may have gained visibility into the committee's internal investigative process, sources, and draft findings during a sensitive period of EU spyware-abuse oversight.

MITRE ATT&CK techniques used in TL-2026-1098

privilege-escalation

T1404 Exploitation for Privilege Escalation

defense-evasion

T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1630 Indicator Removal on Host

Collection

T1409 Stored Application Data; T1414 Clipboard Data; T1417 Input Capture; T1429 Audio Capture; T1512 Video Capture; T1513 Screen Capture; T1517 Access Notifications; T1533 Data from Local System; T1616 Call Control; T1636 Protected User Data

Discovery

T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1424 Process Discovery; T1426 System Information Discovery; T1430 Location Tracking

command-and-control

T1437 Application Layer Protocol; T1481 Web Service; T1509 Non-Standard Port; T1544 Ingress Tool Transfer

Persistence

T1541 Foreground Persistence; T1624 Event Triggered Execution; T1625.001 System Runtime API Hijacking

Resource Development

T1585 Establish Accounts

Reconnaissance

T1589 Gather Victim Identity Information

Exfiltration

T1646 Exfiltration Over C2 Channel

initial-access

T1664 Exploitation for Initial Access

Affected products and versions in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

  • Apple — iOS / iPadOS (HomeKit and MessagesBlastDoorService components)
    Vulnerable versions: iOS 15.1.1; iOS 15.5 (19F77); iOS 15.6; iOS 16.0.3; iOS 16.1 and earlier (MessagesBlastDoorService); iOS 16.3 and earlier (HomeKit)
    Fixed in: iOS 16.1 (MessagesBlastDoorService hardening); iOS 16.3.1 and later (HomeKit message-source validation)
  • NSO Group — Pegasus (iOS implant, MITRE ATT&CK S0289)
    Vulnerable versions: N/A - commercial spyware platform, not versioned software with a patch lifecycle
    Fixed in: N/A

Remediation for Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

Patches

  • Apple iOS/iPadOS 16.3.1 (HomeKit message-source validation hardening, closes PWNYOURHOME's HomeKit phase)
  • Apple iOS 16.1 (earlier hardening of the MessagesBlastDoorService component used in PWNYOURHOME's second phase)
  • Apple iOS/iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3.1 (CVE-2023-23529 WebKit type-confusion zero-day, patched in the same release cycle though not part of the PWNYOURHOME chain)

Immediate actions

  • Update all iPhones and iPads to iOS/iPadOS 16.3.1 or later to receive the HomeKit message-validation hardening that closes the PWNYOURHOME zero-click delivery vector
  • Enable Apple's Lockdown Mode on devices belonging to high-risk individuals such as parliamentarians, journalists, human rights defenders, and civil society figures
  • Treat every Apple 'state-sponsored attacker' threat notification as actionable; immediately submit the device for professional forensic triage rather than dismissing or ignoring it
  • Submit iTunes/Finder backups and iOS sysdiagnose logs to Citizen Lab, Access Now, or the Amnesty International Security Lab for Mobile Verification Toolkit (MVT)-based forensic analysis after any threat notification

Workarounds

  • Enable Lockdown Mode (iOS 16+) to block HomeKit/iMessage zero-click delivery vectors and generate real-time exploitation-attempt notifications
  • Regularly reboot mobile devices to disrupt spyware implants that do not survive a reboot
  • Avoid running outdated iOS versions (e.g., iOS 15.x) known to remain vulnerable to disclosed zero-click chains

Longer-term hardening

  • Establish organization-wide mobile threat defense and rapid forensic-triage capability for parliamentary, government, and civil-society staff
  • Enforce mandatory rapid OS update policies and periodic reboot schedules for high-risk personnel to disrupt non-persistent spyware implants
  • Advance EU-wide legal and export-control restrictions on commercial/mercenary spyware sales consistent with PEGA Committee recommendations
  • Provide device compartmentalization (separate hardened devices with Lockdown Mode enabled for sensitive committee or investigative work)

Weaknesses (CWE) in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

CWE-502, CWE-346

Timeline of Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

  • NSO Group is incorporated in Herzliya, Israel by Niv Carmi, Shalev Hulio, and Omri Lavie, later becoming the developer of the Pegasus spyware platform later used against Kouloglou.
  • Pegasus infections of Catalan politicians including Carles Puigdemont and Diana Riba begin, later dubbed 'CatalanGate,' establishing an early pattern of Pegasus use against elected European officials.
  • Exiled Russian journalist Maria Epifanova is infected with Pegasus while based in Latvia -- the earliest known use of Pegasus against Russian civil society, later linked by shared operator infrastructure to the Kouloglou case.
  • Stelios Kouloglou begins service as a substitute member of the European Parliament's newly formed PEGA Committee of Inquiry (established March 10, 2022) to investigate the use of Pegasus and equivalent spyware.
  • Kouloglou's iPhone, running iOS 15.5 (build 19F77), is infected with Pegasus at approximately 10:16 UTC via the PWNYOURHOME zero-click exploit chain, triggered by a HomeKit lookup of the attacker-controlled address rauharepo888@gmail.com, ten days before a PEGA delegation trip to Greece and Cyprus.
  • Apple releases iOS 16.3.1, hardening HomeKit message-source validation to close the HomeKit phase of the PWNYOURHOME exploit chain; the same release patches the unrelated, actively exploited WebKit zero-day CVE-2023-23529.
  • Apple sends Kouloglou the first of three state-sponsored-attacker threat notifications; he does not recall seeing it.
  • Kouloglou's iPhone is infected with Pegasus a second time (through March 7, 07:30 UTC), via an exploit chain assessed as likely identical to the October 2022 attack, coinciding with PEGA committee deliberations in Brussels on the panel's final report.
  • Citizen Lab publishes 'Triple Threat,' publicly documenting the PWNYOURHOME, FINDMYPWN, and LATENTIMAGE zero-click exploit chains used by NSO Group Pegasus operators against iOS 15 and iOS 16 devices in 2022.
  • Kouloglou's term on the PEGA Committee ends as the committee concludes its inquiry and publishes its final report.
  • Apple sends Kouloglou a second state-sponsored-attacker threat notification.
  • Apple sends Kouloglou a third state-sponsored-attacker threat notification.
  • Citizen Lab and Access Now publish 'By Whose Authority?', identifying at least seven Russian- and Belarusian-speaking journalists and activists in Europe infected with Pegasus, and revealing that the rauharepo888@gmail.com address later tied to Kouloglou was also used in that campaign.
  • Kouloglou submits his iPhone's forensic artifacts to Citizen Lab, which confirms both the October 2022 and March 2023 Pegasus infections with high confidence.
  • Citizen Lab publicly discloses the espionage campaign against Kouloglou -- the first publicly confirmed case of a sitting PEGA Committee member being infected with Pegasus during active service on the spyware inquiry -- with coverage from CyberScoop, The Hacker News, TechCrunch, The Record, and other outlets.

Sources cited for Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

Threats related to Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against

Detection coverage for TL-2026-1098

As of 2026-07-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1098 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats