Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios Kouloglou
Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against (TL-2026-1098), also tracked as PWNYOURHOME Campaign, is a high-severity malware campaign, first published 2026-07-03. It has no confirmed attribution, affects Apple iOS / iPadOS (HomeKit and MessagesBlastDoorService components), maps to 30 MITRE ATT&CK techniques (T1404, T1406, T1409), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1098
- Threat ID
- TL-2026-1098
- Also known as
- PWNYOURHOME Campaign, Espionage Against the European Parliament, Kouloglou Pegasus Case
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-03
- Last reviewed
- 2026-07-03
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, legislative, civil society, news - media, non-profit organisation
- Target regions
- Europe, European Union, greece, belgium
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
Malware and tooling: Chrysaor
Citizen Lab forensic analysis confirmed NSO Group's Pegasus spyware infected the iPhone of Stelios Kouloglou, a substitute member of the European Parliament's PEGA Committee investigating spyware abuse, on October 21, 2022 and again on March 6-7, 2023, via the zero-click PWNYOURHOME exploit chain (HomeKit -> iMessage BlastDoor -> mediaserverd). The operator has not been attributed to a specific government, but the attacker-controlled email rauharepo888@gmail.com links the case to a separate NSO customer campaign against exiled Russian and Belarusian journalists disclosed in May 2024.
How Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against works
The Citizen Lab, in a report published July 2-3, 2026, disclosed forensic evidence that the iPhone of Stelios Kouloglou -- a Greek journalist and former Member of the European Parliament who served as a substitute member of the PEGA Committee (the European Parliament's Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, active March 24, 2022 to July 18, 2023) -- was infected twice with NSO Group's Pegasus spyware. The first infection occurred on or around October 21, 2022 at approximately 10:16 UTC, ten days before Kouloglou was to join a PEGA delegation trip to Greece and Cyprus and while he was hospitalized for elective surgery. The second infection occurred between March 6 09:49 UTC and March 7 07:30 UTC 2023, coinciding with PEGA committee deliberations in Brussels on the panel's final report. Both infections were assessed by Citizen Lab with high confidence and are believed to use the same exploit chain. This is the first publicly documented case of a sitting PEGA Committee member being confirmed as a Pegasus victim during active service on the inquiry.
Both infections were delivered via PWNYOURHOME, a novel two-phase zero-click exploit chain first documented by Citizen Lab in its April 2023 'Triple Threat' report alongside two related chains (FINDMYPWN and LATENTIMAGE) used by NSO Group against iOS 15 and early iOS 16 in 2022. PWNYOURHOME's first phase abuses Apple's HomeKit smart-home framework: the attacker performs a HomeKit-linked lookup of an attacker-controlled Apple ID/email address (rauharepo888@gmail.com in this case), delivering a crafted NSKeyedArchiver-serialized message that is processed by the HomeKit daemon (homed) without adequate origin validation. This first stage crashes/manipulates the HomeKit daemon and stages a second payload delivered through iMessage, where a maliciously crafted PNG image is processed by the MessagesBlastDoorService sandbox, causing it to crash and executing attacker code. The exploit chain culminates in code execution being handed off to the mediaserverd process, from which the Pegasus implant is deployed with no visible interaction required from the victim. Apple mitigated the HomeKit phase of the attack in iOS 16.3.1 (released February 13, 2023) by adding validation that declines to decode HomeKit messages arriving from implausible sources; the MessagesBlastDoorService component was likely hardened earlier, around iOS 16.1. Both of Kouloglou's infections occurred while his device was running the outdated iOS 15.5 (build 19F77), which remained vulnerable to the full PWNYOURHOME chain. Apple's Lockdown Mode, introduced in iOS 16, is documented by Citizen Lab to block PWNYOURHOME and surface real-time attack notifications, though researchers suspect NSO Group has worked to fingerprint and evade Lockdown Mode's notification behavior.
Citizen Lab's investigation, governed by University of Toronto Research Ethics Board protocols, was unable to attribute the intrusions to a specific government or confirm which NSO Group customer conducted the operation. Investigators explicitly found no evidence implicating the Greek government or that Greece is an NSO Group customer, but noted that infection activity appears to intersect at least two European jurisdictions (Greece and Belgium), consistent with an NSO customer holding multi-jurisdiction licensing or a customer operating extraterritorially against a target traveling between EU institutions. The strongest attribution lead is infrastructural: the same rauharepo888@gmail.com HomeKit-lookup address used against Kouloglou also appears (as 'Email 1') in a May 2024 joint Citizen Lab/Access Now report, 'By Whose Authority?', which documented Pegasus infections of at least seven Russian- and Belarusian-speaking journalists and civil society figures exiled in Europe, including Latvia-based Russian journalist Maria Epifanova (infected August 2020, the earliest known Pegasus use against Russian civil society) and Poland-based Belarusian journalist Natalya Radina. Because Citizen Lab assesses that these HomeKit delivery email addresses are operator-specific and not shared/resold between NSO customers, the shared address strongly suggests the same Pegasus operator/customer targeted both the Russian/Belarusian civil-society network and a sitting member of the EU body created specifically to investigate spyware abuse.
Apple sent Kouloglou three separate state-sponsored-attacker threat notifications (March 2, 2023; August 29, 2023; and April 10, 2024), none of which he recalls seeing or acting on -- illustrating a recurring gap between vendor threat notifications and real-world remediation among high-risk targets. The case adds to a long pattern of Pegasus and other commercial spyware (Predator/Intellexa, Candiru) being used against PEGA Committee members and associated European political figures, including Carles Puigdemont, Diana Riba, and Jordi Solé (Catalan MEPs targeted 2019-2020, 'CatalanGate'), Nikos Androulakis (Predator), Elena Yoncheva (Pegasus, October 2023), Nathalie Loiseau (Pegasus, February 2024), Daniel Freund (Candiru, May 2024), and Greek journalist Thanasis Koukakis (Intellexa Predator, March 2022). Citizen Lab founder Ron Deibert characterized the likely motive as an attempt to breach parliamentary privilege and monitor the committee's investigation into spyware abuse itself -- a direct challenge to EU efforts at regulatory accountability for the commercial spyware industry. Because Kouloglou's infections occurred while he was interacting with confidential PEGA committee materials, deliberations, and travel logistics, the attacker(s) may have gained visibility into the committee's internal investigative process, sources, and draft findings during a sensitive period of EU spyware-abuse oversight.
MITRE ATT&CK techniques used in TL-2026-1098
privilege-escalation
T1404 Exploitation for Privilege Escalation
defense-evasion
T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1630 Indicator Removal on Host
Collection
T1409 Stored Application Data; T1414 Clipboard Data; T1417 Input Capture; T1429 Audio Capture; T1512 Video Capture; T1513 Screen Capture; T1517 Access Notifications; T1533 Data from Local System; T1616 Call Control; T1636 Protected User Data
Discovery
T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1424 Process Discovery; T1426 System Information Discovery; T1430 Location Tracking
command-and-control
T1437 Application Layer Protocol; T1481 Web Service; T1509 Non-Standard Port; T1544 Ingress Tool Transfer
Persistence
T1541 Foreground Persistence; T1624 Event Triggered Execution; T1625.001 System Runtime API Hijacking
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information
Exfiltration
T1646 Exfiltration Over C2 Channel
initial-access
Affected products and versions in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
- Apple — iOS / iPadOS (HomeKit and MessagesBlastDoorService components)
Vulnerable versions: iOS 15.1.1; iOS 15.5 (19F77); iOS 15.6; iOS 16.0.3; iOS 16.1 and earlier (MessagesBlastDoorService); iOS 16.3 and earlier (HomeKit)
Fixed in: iOS 16.1 (MessagesBlastDoorService hardening); iOS 16.3.1 and later (HomeKit message-source validation) - NSO Group — Pegasus (iOS implant, MITRE ATT&CK S0289)
Vulnerable versions: N/A - commercial spyware platform, not versioned software with a patch lifecycle
Fixed in: N/A
Remediation for Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
Patches
- Apple iOS/iPadOS 16.3.1 (HomeKit message-source validation hardening, closes PWNYOURHOME's HomeKit phase)
- Apple iOS 16.1 (earlier hardening of the MessagesBlastDoorService component used in PWNYOURHOME's second phase)
- Apple iOS/iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3.1 (CVE-2023-23529 WebKit type-confusion zero-day, patched in the same release cycle though not part of the PWNYOURHOME chain)
Immediate actions
- Update all iPhones and iPads to iOS/iPadOS 16.3.1 or later to receive the HomeKit message-validation hardening that closes the PWNYOURHOME zero-click delivery vector
- Enable Apple's Lockdown Mode on devices belonging to high-risk individuals such as parliamentarians, journalists, human rights defenders, and civil society figures
- Treat every Apple 'state-sponsored attacker' threat notification as actionable; immediately submit the device for professional forensic triage rather than dismissing or ignoring it
- Submit iTunes/Finder backups and iOS sysdiagnose logs to Citizen Lab, Access Now, or the Amnesty International Security Lab for Mobile Verification Toolkit (MVT)-based forensic analysis after any threat notification
Workarounds
- Enable Lockdown Mode (iOS 16+) to block HomeKit/iMessage zero-click delivery vectors and generate real-time exploitation-attempt notifications
- Regularly reboot mobile devices to disrupt spyware implants that do not survive a reboot
- Avoid running outdated iOS versions (e.g., iOS 15.x) known to remain vulnerable to disclosed zero-click chains
Longer-term hardening
- Establish organization-wide mobile threat defense and rapid forensic-triage capability for parliamentary, government, and civil-society staff
- Enforce mandatory rapid OS update policies and periodic reboot schedules for high-risk personnel to disrupt non-persistent spyware implants
- Advance EU-wide legal and export-control restrictions on commercial/mercenary spyware sales consistent with PEGA Committee recommendations
- Provide device compartmentalization (separate hardened devices with Lockdown Mode enabled for sensitive committee or investigative work)
Weaknesses (CWE) in Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
CWE-502, CWE-346
Timeline of Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
- NSO Group is incorporated in Herzliya, Israel by Niv Carmi, Shalev Hulio, and Omri Lavie, later becoming the developer of the Pegasus spyware platform later used against Kouloglou.
- Pegasus infections of Catalan politicians including Carles Puigdemont and Diana Riba begin, later dubbed 'CatalanGate,' establishing an early pattern of Pegasus use against elected European officials.
- Exiled Russian journalist Maria Epifanova is infected with Pegasus while based in Latvia -- the earliest known use of Pegasus against Russian civil society, later linked by shared operator infrastructure to the Kouloglou case.
- Stelios Kouloglou begins service as a substitute member of the European Parliament's newly formed PEGA Committee of Inquiry (established March 10, 2022) to investigate the use of Pegasus and equivalent spyware.
- Kouloglou's iPhone, running iOS 15.5 (build 19F77), is infected with Pegasus at approximately 10:16 UTC via the PWNYOURHOME zero-click exploit chain, triggered by a HomeKit lookup of the attacker-controlled address rauharepo888@gmail.com, ten days before a PEGA delegation trip to Greece and Cyprus.
- Apple releases iOS 16.3.1, hardening HomeKit message-source validation to close the HomeKit phase of the PWNYOURHOME exploit chain; the same release patches the unrelated, actively exploited WebKit zero-day CVE-2023-23529.
- Apple sends Kouloglou the first of three state-sponsored-attacker threat notifications; he does not recall seeing it.
- Kouloglou's iPhone is infected with Pegasus a second time (through March 7, 07:30 UTC), via an exploit chain assessed as likely identical to the October 2022 attack, coinciding with PEGA committee deliberations in Brussels on the panel's final report.
- Citizen Lab publishes 'Triple Threat,' publicly documenting the PWNYOURHOME, FINDMYPWN, and LATENTIMAGE zero-click exploit chains used by NSO Group Pegasus operators against iOS 15 and iOS 16 devices in 2022.
- Kouloglou's term on the PEGA Committee ends as the committee concludes its inquiry and publishes its final report.
- Apple sends Kouloglou a second state-sponsored-attacker threat notification.
- Apple sends Kouloglou a third state-sponsored-attacker threat notification.
- Citizen Lab and Access Now publish 'By Whose Authority?', identifying at least seven Russian- and Belarusian-speaking journalists and activists in Europe infected with Pegasus, and revealing that the rauharepo888@gmail.com address later tied to Kouloglou was also used in that campaign.
- Kouloglou submits his iPhone's forensic artifacts to Citizen Lab, which confirms both the October 2022 and March 2023 Pegasus infections with high confidence.
- Citizen Lab publicly discloses the espionage campaign against Kouloglou -- the first publicly confirmed case of a sitting PEGA Committee member being infected with Pegasus during active service on the spyware inquiry -- with coverage from CyberScoop, The Hacker News, TechCrunch, The Record, and other outlets.
Sources cited for Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
- Pegasus spyware used to target PEGA committee member
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus
- Triple Threat: NSO Group's Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains
- By Whose Authority? Pegasus targeting of Russian & Belarusian-speaking opposition activists and independent media in Europe
- European Parliament Member Investigating Spyware Was Hacked With Pegasus
- EU lawmaker investigating surveillance hacked by Israeli spyware, report says
- Politician who investigated spyware abuses had his phone hacked with Pegasus spyware
- Spyware found on phone of European Parliament member probing it
- Pegasus Spyware Hacked MEP Serving on European Parliament PEGA Committee
- Former MEP Investigating Spyware Abuses Has Phone Hacked With Pegasus
- Lawmaker Probing Pegasus Spyware Infected Using Same Malware
- Report: Pegasus Spyware Targets Exiled Journalists from Russia, Latvia, Belarus
- About the security content of iOS 16.3.1 and iPadOS 16.3.1
- CVE-2023-23529 - Apple WebKit Type Confusion Vulnerability (Actively Exploited)
- Pegasus for iOS, Software S0289
Threats related to Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain)
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors
Detection coverage for TL-2026-1098
As of 2026-07-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1098 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.