European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain) — Threadlinqs Intelligence
As of 2026-07-03, European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain) is a critical-severity zero day threat attributed to Unknown Pegasus Operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1099 · Severity: CRITICAL · Status: ACTIVE · Category: ZERO_DAY
Attribution: Unknown Pegasus Operator · ESPIONAGE
Stelios Kouloglou, a former Member of the European Parliament and substitute member of the PEGA Committee of Inquiry into Pegasus spyware, had his iPhone compromised with NSO Group's Pegasus spyware
In a research report published July 3, 2026, Citizen Lab disclosed that Stelios Kouloglou -- a Greek investigative journalist and former Member of the European Parliament who served as a substitute member of the PEGA Committee (the European Parliament's Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware) from March 24, 2022 to July 18, 2023 -- was infected with NSO Group's Pegasus mercenary spyware on at least two occasions while the committee was actively investigating spyware abuse in the EU.
Both infections were delivered via PWNYOURHOME, a novel two-phase zero-click exploit chain first documented by Citizen Lab in April 2023 as one of a trio of iOS 15/16 exploit chains NSO Group deployed in 2022 (alongside FINDMYPWN and LATENTIMAGE). PWNYOURHOME begins with a specially crafted NSKeyedArchive object delivered to the device and processed by HomeKit's homed daemon via NSKeyedUnarchiver deserialization -- specifically routed through -[HMDHomeManager _handleHomeDataSync:], which decoded a class not normally used within HomeKit. An attacker-controlled Apple ID/email address is added to the target's HomeKit invitation/lookup state shortly (minutes) before payload execution. The second phase downloads PNG images containing malicious MakerNote metadata through iMessage; parsing these images crashes MessagesBlastDoorService (Apple's iMessage attachment sandbox introduced after FORCEDENTRY) and achieves code execution by repurposing PAC (Pointer Authentication Code)-valid pointers already resident in memory -- e.g., signed pointers to callback functions inside constant structs -- to defeat ARM64e pointer authentication without needing to forge new signed pointers. The payload is subsequently launched via the mediaserverd process.
Kouloglou's device was running iOS 15.5 (build 19F77) -- a version vulnerable to both exploit phases -- during both intrusions. The first infection occurred October 21, 2022 at 10:16 UTC, forensically anchored by a HomeKit lookup for the attacker-controlled identifier rauharepo888@gmail.com, followed roughly two minutes later by anomalous mobile data usage consistent with Pegasus process activity. This infection occurred during a hospital stay and preceded the PEGA Committee's first hearings (October 26-27, 2022) and a committee fact-finding visit to Greece and Cyprus (November 1-4, 2022) by days. A second, forensically similar intrusion -- assessed by Citizen Lab as "likely linked to the same exploit" -- occurred March 6 (09:49) through March 7 (07:30), 2023, during a Brussels visit, again on iOS 15.5 (19F77).
Apple sent Kouloglou state-sponsored threat notifications on three occasions: March 2, 2023 (before he was aware of the specific forensic findings), August 29, 2023, and April 10, 2024. Apple mitigated the HomeKit/homed deserialization issue exploited in PWNYOURHOME's first phase in iOS 16.3.1 (released February 13, 2023) by adding a new method, -[HMDHomeManager _shouldDecodeMessage:error:], that declines to decode HomeKit messages arriving from implausible sources; the MessagesBlastDoorService issue exploited in the second phase was fixed earlier, likely in iOS 16.1 (released October 24, 2022). Citizen Lab shared forensic PWNYOURHOME artifacts with Apple in October 2022 and additional artifacts in January 2023, contributing to the 16.3.1 fix. No CVE identifier is known to have been publicly assigned to either component of the PWNYOURHOME chain. Targets with iOS 16 Lockdown Mode enabled received real-time exploitation warnings during PWNYOURHOME attempts, and Citizen Lab has not observed a successful PWNYOURHOME infection against any device with Lockdown Mode enabled.
The forensically critical link in this report is infrastructure/tradecraft overlap: the same attacker-controlled HomeKit lookup identifier, rauharepo888@gmail.com, used against Kouloglou in October 2022 also appears in Citizen Lab and Access Now's May 30, 2024 joint report, "By Whose Authority?
Weaknesses (CWE)
CWE-502, CWE-822
Target sectors: government administration, legislativeoversight, mediaandjournalism, civil society, ngo
Target regions: Europe, greece, belgium, latvia, poland, lithuania
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, T1456, T1477, T1664, T1404, T1624, T1628, T1631, T1634, T1517, T1420