European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain)

European Parliament Member Investigating Pegasus Spyware (TL-2026-1099), also tracked as PWNYOURHOME, is a critical-severity zero-day vulnerability, first published 2026-07-03. It has no confirmed attribution, affects Apple iOS (HomeKit / homed daemon), maps to 21 MITRE ATT&CK techniques (T1404, T1409, T1414), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1099

Threat ID
TL-2026-1099
Also known as
PWNYOURHOME, Kouloglou Pegasus Case, PEGA Committee Pegasus Hack
Severity
CRITICAL
Status
ACTIVE
Category
ZERO_DAY
First published
2026-07-03
Last reviewed
2026-07-03
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, legislativeoversight, mediaandjournalism, civil society, ngo
Target regions
Europe, greece, belgium, latvia, poland, lithuania
Detection rules
9
Indicators of compromise
20

Malware and tooling in European Parliament Member Investigating Pegasus Spyware

Malware and tooling: Chrysaor, Pegasus for iOS (MITRE ATT&CK S0289)

Stelios Kouloglou, a former Member of the European Parliament and substitute member of the PEGA Committee of Inquiry into Pegasus spyware, had his iPhone compromised with NSO Group's Pegasus spyware via the two-phase zero-click PWNYOURHOME exploit chain (HomeKit NSKeyedArchive deserialization followed by MessagesBlastDoorService exploitation) on October 21, 2022 and again March 6-7, 2023. Citizen Lab forensic analysis found a shared attacker-controlled HomeKit lookup identifier linking this intrusion to a Pegasus operator previously documented targeting Russian and Belarusian-speaking exiled journalists and activists in Europe; no government has been attributed and researchers found no evidence implicating Greece.

How European Parliament Member Investigating Pegasus Spyware works

In a research report published July 3, 2026, Citizen Lab disclosed that Stelios Kouloglou -- a Greek investigative journalist and former Member of the European Parliament who served as a substitute member of the PEGA Committee (the European Parliament's Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware) from March 24, 2022 to July 18, 2023 -- was infected with NSO Group's Pegasus mercenary spyware on at least two occasions while the committee was actively investigating spyware abuse in the EU.

Both infections were delivered via PWNYOURHOME, a novel two-phase zero-click exploit chain first documented by Citizen Lab in April 2023 as one of a trio of iOS 15/16 exploit chains NSO Group deployed in 2022 (alongside FINDMYPWN and LATENTIMAGE). PWNYOURHOME begins with a specially crafted NSKeyedArchive object delivered to the device and processed by HomeKit's homed daemon via NSKeyedUnarchiver deserialization -- specifically routed through -[HMDHomeManager _handleHomeDataSync:], which decoded a class not normally used within HomeKit. An attacker-controlled Apple ID/email address is added to the target's HomeKit invitation/lookup state shortly (minutes) before payload execution. The second phase downloads PNG images containing malicious MakerNote metadata through iMessage; parsing these images crashes MessagesBlastDoorService (Apple's iMessage attachment sandbox introduced after FORCEDENTRY) and achieves code execution by repurposing PAC (Pointer Authentication Code)-valid pointers already resident in memory -- e.g., signed pointers to callback functions inside constant structs -- to defeat ARM64e pointer authentication without needing to forge new signed pointers. The payload is subsequently launched via the mediaserverd process.

Kouloglou's device was running iOS 15.5 (build 19F77) -- a version vulnerable to both exploit phases -- during both intrusions. The first infection occurred October 21, 2022 at 10:16 UTC, forensically anchored by a HomeKit lookup for the attacker-controlled identifier rauharepo888@gmail.com, followed roughly two minutes later by anomalous mobile data usage consistent with Pegasus process activity. This infection occurred during a hospital stay and preceded the PEGA Committee's first hearings (October 26-27, 2022) and a committee fact-finding visit to Greece and Cyprus (November 1-4, 2022) by days. A second, forensically similar intrusion -- assessed by Citizen Lab as "likely linked to the same exploit" -- occurred March 6 (09:49) through March 7 (07:30), 2023, during a Brussels visit, again on iOS 15.5 (19F77).

Apple sent Kouloglou state-sponsored threat notifications on three occasions: March 2, 2023 (before he was aware of the specific forensic findings), August 29, 2023, and April 10, 2024. Apple mitigated the HomeKit/homed deserialization issue exploited in PWNYOURHOME's first phase in iOS 16.3.1 (released February 13, 2023) by adding a new method, -[HMDHomeManager _shouldDecodeMessage:error:], that declines to decode HomeKit messages arriving from implausible sources; the MessagesBlastDoorService issue exploited in the second phase was fixed earlier, likely in iOS 16.1 (released October 24, 2022). Citizen Lab shared forensic PWNYOURHOME artifacts with Apple in October 2022 and additional artifacts in January 2023, contributing to the 16.3.1 fix. No CVE identifier is known to have been publicly assigned to either component of the PWNYOURHOME chain. Targets with iOS 16 Lockdown Mode enabled received real-time exploitation warnings during PWNYOURHOME attempts, and Citizen Lab has not observed a successful PWNYOURHOME infection against any device with Lockdown Mode enabled.

The forensically critical link in this report is infrastructure/tradecraft overlap: the same attacker-controlled HomeKit lookup identifier, rauharepo888@gmail.com, used against Kouloglou in October 2022 also appears in Citizen Lab and Access Now's May 30, 2024 joint report, "By Whose Authority? Pegasus Targeting of Russian & Belarusian-Speaking Opposition Activists and Independent Media in Europe," which documented seven Russian- and Belarusian-speaking journalists and activists in Latvia, Poland, and Lithuania targeted and/or infected with Pegasus between August 2020 and January 2023, including Riga-based Russian journalist Maria Epifanova (CEO of Novaya Gazeta Europe, infected August 2020 -- the earliest known Pegasus use against Russian civil society), Warsaw-based exiled Belarusian journalist Natallia Radzina, Warsaw-based Belarusian opposition figure Andrei Sannikov, and Riga-based journalist Evgeny Erlikh. Citizen Lab assesses the shared identifier as "unique to specific operators," indicating the same Pegasus customer/operator targeted both Kouloglou and this cluster of exiled Russian/Belarusian civil-society figures, and that infections spanning multiple EU jurisdictions (Greece and Belgium, plus the earlier Latvia/Poland/Lithuania cases) indicate the responsible NSO customer held a license permitting operations across multiple EU member states.

Citizen Lab explicitly states it is not attributing the Kouloglou infections to a specific NSO Group government customer and found no indications the Greek government is responsible, despite Kouloglou's own public statement to Recorded Future News that he believes the Greek government is responsible. The PEGA Committee adopted its recommendations report on May 8, 2023; the European Commission has been criticized by Citizen Lab researcher John Scott-Railton and other politicians/experts for largely ignoring those recommendations. Citizen Lab's key recommendations include immediate forensic screening of MEPs' and staff devices via the European Parliament's DG ITEC, a formal European Parliament investigation into spyware attacks on its own legislative processes, annual public cyber threat reporting on Parliament security, increased voluntary spyware screening with public statistics, enabling iOS Lockdown Mode / Android Advanced Protection on at-risk devices, and improved UX for state-sponsored threat notifications from platform vendors.

MITRE ATT&CK techniques used in TL-2026-1099

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Collection

T1409 Stored Application Data; T1414 Clipboard Data; T1417 Input Capture; T1430 Location Tracking; T1517 Access Notifications; T1533 Data from Local System; T1636 Protected User Data

Discovery

T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1426 System Information Discovery

Command and Control

T1437 Application Layer Protocol; T1521 Encrypted Channel

Initial Access

T1456 Drive-By Compromise; T1477 Exploit via Radio Interfaces; T1664 Exploitation for Initial Access

Credential Access

T1517 Access Notifications; T1634 Credentials from Password Store

Persistence

T1624 Event Triggered Execution

Defense Evasion

T1628 Hide Artifacts; T1631 Process Injection

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in European Parliament Member Investigating Pegasus Spyware

  • Apple — iOS (HomeKit / homed daemon)
    Vulnerable versions: iOS 15.x; iOS 16.0 - 16.3
    Fixed in: iOS 16.3.1 and later
  • Apple — iOS (iMessage / MessagesBlastDoorService)
    Vulnerable versions: iOS 15.x; iOS 16.0
    Fixed in: iOS 16.1 and later
  • NSO Group — Pegasus for iOS (spyware payload delivered via PWNYOURHOME)
    Vulnerable versions: N/A - commercial spyware payload, not versioned publicly
    Fixed in: N/A

Remediation for European Parliament Member Investigating Pegasus Spyware

Patches

  • iOS 16.1 (released October 24, 2022) -- fixed the MessagesBlastDoorService vulnerability exploited in PWNYOURHOME phase two
  • iOS 16.3.1 (released February 13, 2023) -- added -[HMDHomeManager _shouldDecodeMessage:error:] to HomeKit, rejecting implausible-source messages and closing the NSKeyedArchive deserialization issue exploited in PWNYOURHOME phase one

Immediate actions

  • Update all iOS devices to iOS 16.3.1 or later to receive the HomeKit NSKeyedArchive deserialization mitigation that closes PWNYOURHOME's first exploitation phase
  • Ensure devices are on iOS 16.1 or later to receive the MessagesBlastDoorService fix closing PWNYOURHOME's second exploitation phase
  • Enable Lockdown Mode on iOS for high-risk individuals (politicians, journalists, human rights defenders, civil society) -- Citizen Lab has observed no successful PWNYOURHOME infections against Lockdown Mode-enabled devices
  • Enable Advanced Protection on Android for equivalent at-risk users
  • Conduct immediate forensic screening (e.g., via Mobile Verification Toolkit / MVT) of devices belonging to MEPs, parliamentary staff, and committee members handling sensitive oversight work
  • Treat any Apple 'state-sponsored threat notification' as a credible signal requiring immediate forensic triage, not user-side dismissal

Workarounds

  • Enable Lockdown Mode (iOS 16+) which provides real-time warnings on PWNYOURHOME exploitation attempts and has blocked all observed successful infections
  • Restrict or disable HomeKit home-sharing invitations from unknown/unverified Apple IDs where feasible
  • Reboot devices regularly, as Pegasus historically has limited reboot-survival persistence on iOS, increasing the value of periodic reboots as a stopgap

Longer-term hardening

  • European Parliament DG ITEC to establish a standing, voluntary, and confidential device-screening program for members and staff with published aggregate statistics
  • European Parliament to open a formal investigation into spyware attacks targeting its own legislative and oversight processes
  • Institute annual public cyber threat reporting covering spyware targeting of Parliament members and staff
  • Push for EU-level binding export-control and procurement restrictions on commercial spyware vendors licensing to EU member state customers
  • Vendors (Apple, Google) to continue hardening zero-click attack surfaces (BlastDoor-style sandboxing) around messaging, HomeKit, Find My, and other background daemons reachable without user interaction
  • Improve UX and actionability of state-sponsored threat notification programs across platform vendors so recipients can rapidly obtain forensic support

Weaknesses (CWE) in European Parliament Member Investigating Pegasus Spyware

CWE-502, CWE-822

Timeline of European Parliament Member Investigating Pegasus Spyware

  • Earliest known Pegasus infection linked to this operator cluster: Riga-based exiled Russian journalist Maria Epifanova (CEO, Novaya Gazeta Europe) infected -- assessed by Citizen Lab as the earliest known use of Pegasus against Russian civil society, later documented in the May 2024 'By Whose Authority?' report.
  • LATENTIMAGE, a low-forensic-trace iOS 15.1.1 zero-click exploit chain in the same 2022 NSO exploit trio as PWNYOURHOME, documented in a single case (Citizen Lab, April 2023 report).
  • FINDMYPWN, a two-phase iOS 15.5/15.6 zero-day exploit chain targeting the Find My (fmfd) daemon and MessagesBlastDoorService, first used against two Centro PRODH staff members between June and September 2022.
  • First confirmed Pegasus infection of Stelios Kouloglou's iPhone (iOS 15.5, build 19F77) via PWNYOURHOME at 10:16 UTC, forensically anchored by a HomeKit lookup for attacker-controlled identifier rauharepo888@gmail.com followed ~2 minutes later by anomalous Pegasus-linked mobile data usage; occurred during a hospital stay.
  • Apple releases iOS 16.1, which fixed the MessagesBlastDoorService vulnerability exploited in PWNYOURHOME's second phase (though Kouloglou's device remained on the vulnerable iOS 15.5).
  • European Parliament PEGA Committee (Committee of Inquiry to investigate Pegasus and equivalent spyware) commences its first hearings, days after Kouloglou's first infection.
  • PEGA Committee conducts a fact-finding visit to Greece and Cyprus.
  • Citizen Lab shares additional PWNYOURHOME forensic artifacts with Apple, following an initial artifact disclosure in October 2022.
  • Apple releases iOS 16.3.1, adding -[HMDHomeManager _shouldDecodeMessage:error:] to HomeKit to reject implausible-source messages, mitigating the NSKeyedArchive deserialization vulnerability exploited in PWNYOURHOME's first phase.
  • Kouloglou receives his first Apple state-sponsored threat notification.
  • Second confirmed Pegasus infection of Kouloglou's iPhone (still iOS 15.5, 19F77) via a PWNYOURHOME-consistent exploit, spanning March 6 09:49 through March 7 07:30, during a Brussels visit.
  • PEGA Committee adopts its first recommendations report on spyware abuse in the EU.
  • Kouloglou receives a second Apple state-sponsored threat notification.
  • Kouloglou receives a third Apple state-sponsored threat notification.
  • Citizen Lab and Access Now jointly publish 'By Whose Authority? Pegasus Targeting of Russian & Belarusian-Speaking Opposition Activists and Independent Media in Europe,' documenting seven targeted/infected individuals in Latvia, Poland, and Lithuania and containing the same attacker-controlled HomeKit identifier later matched to the Kouloglou case.
  • Citizen Lab publishes 'Espionage Against the European Parliament,' disclosing the Kouloglou infections and the infrastructure overlap with the 2024 Russian/Belarusian journalist targeting cluster; covered same-day by The Hacker News, The Record, and others.

Sources cited for European Parliament Member Investigating Pegasus Spyware

Threats related to European Parliament Member Investigating Pegasus Spyware

Detection coverage for TL-2026-1099

As of 2026-07-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1099 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats