Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee
Pegasus Spyware Used Against Former MEP Stelios Kouloglou (TL-2026-1110), also tracked as PWNYOURHOME, is a critical-severity malware campaign, first published 2026-07-05. It has no confirmed attribution, affects Apple iPhone (iOS), maps to 25 MITRE ATT&CK techniques (T1404, T1407, T1409), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1110
- Threat ID
- TL-2026-1110
- Also known as
- PWNYOURHOME, Espionage Against the European Parliament
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-05
- Last reviewed
- 2026-07-05
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, legislative, ngo, news - media, civil society
- Target regions
- Europe, greece, belgium, latvia, lithuania, poland, spain, mexico
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Pegasus Spyware Used Against Former MEP Stelios Kouloglou
Malware and tooling: Chrysaor, Predator, FINDMYPWN, LATENTIMAGE, PWNYOURHOME, Pegasus Anonymizing Transmission Network (PATN)
Citizen Lab forensic analysis confirmed with high confidence that former European Parliament member Stelios Kouloglou, a substitute member of the PEGA Committee investigating spyware abuse, was infected with NSO Group's Pegasus spyware via the PWNYOURHOME zero-click exploit chain on October 21, 2022 and again on March 6-7, 2023. Citizen Lab found no evidence of Greek government involvement but identified an attacker-controlled HomeKit-linked email address that overlaps with a prior Pegasus campaign targeting Russian- and Belarusian-speaking exiled journalists and activists across Europe.
How Pegasus Spyware Used Against Former MEP Stelios Kouloglou works
Stelios Kouloglou, a Greek investigative journalist and Member of the European Parliament (2015-2024) who served as a substitute member of the European Parliament's PEGA Committee investigating spyware abuse (March 24, 2022 - July 18, 2023), was targeted twice with NSO Group's Pegasus mercenary spyware while the committee was actively drafting and negotiating its findings on EU spyware abuse.
The first infection occurred on October 21, 2022 while Kouloglou was hospitalized in Greece, ten days before he personally joined a Cyprus-Greece PEGA delegation trip and during the committee's initial report drafting. The second infection occurred March 6-7, 2023 while he traveled from Athens to Brussels during final PEGA report negotiations, overlapping with rapporteur Sophie in 't Veld's delegation visit to Greece. Both infections used the PWNYOURHOME zero-click exploit chain: a specially crafted NSKeyedArchive delivered to the iPhone's HomeKit daemon (homed), triggered via a lookup of the attacker-controlled address rauharepo888@gmail.com (recorded at 2022-10-21 10:16 UTC), followed roughly two minutes later by malicious content landing in MessagesBlastDoorService and observable Pegasus mobile-data network activity. The target device ran iOS 15.5 (build 19F77) at the time of both infections.
PWNYOURHOME was one of three novel NSO zero-click exploit chains publicly disclosed by Citizen Lab in its April 2023 'Triple Threat' report, alongside FINDMYPWN (which abuses the Find My daemon fmfd before pivoting into MessagesBlastDoorService, used against Mexican human-rights defenders at Centro PRODH in mid-2022) and LATENTIMAGE (a low-trace single-case chain observed in January 2022 against an out-of-date iOS 15.1.1 device). All three chains circumvent Apple's Pointer Authentication Code (PAC) mitigations by repurposing known-offset signed pointers already present in the iOS shared cache, allowing code execution despite modern exploit mitigations. Apple addressed the HomeKit vector in iOS 16.3.1 and the MessagesBlastDoorService vector earlier, around iOS 16.1.
Citizen Lab's attribution assessment states explicitly that it is 'not attributing these infections to a particular government at this time' and found 'no indications that the Greek Government is responsible' and no indication Greece has ever been an NSO Group customer. However, the rauharepo888@gmail.com HomeKit identifier used against Kouloglou reappears as a redacted Apple ID in Citizen Lab and Access Now's May 2024 report 'By Whose Authority?' documenting Pegasus targeting of at least seven Russian- and Belarusian-speaking exiled journalists and opposition activists across Latvia, Lithuania, and Poland between 2020 and 2023 (including Maria Epifanova, Natalya Radina, and Evgeniy Erlich), suggesting a single NSO customer operating with multi-country licensing across EU jurisdictions. Kouloglou received Apple threat notifications on March 2, 2023, August 29, 2023, and April 10, 2024 -- each arriving months after the actual targeting, consistent with Apple's standard batch-notification delay.
Kouloglou is the first publicly identified PEGA Committee member confirmed compromised while actively serving on the inquiry into spyware abuses, but not the only one: PEGA Committee Chair Nathalie Loiseau, Vice-Chair Diana Riba, substitute member Jordi Sole, and member Carles Puigdemont were all separately confirmed as Pegasus targets (the latter three tied to the 'CatalanGate' campaign against Catalan independence figures), Bulgarian MEP Elena Yoncheva was targeted with Pegasus in late October 2023, and German MEP Daniel Freund disclosed targeting with Candiru spyware in May 2024. The case sits alongside Greece's own domestic 'Predatorgate' scandal, in which Intellexa's Predator spyware (a different vendor and platform) was used to surveil PASOK leader and MEP Nikos Androulakis and journalist Thanasis Koukakis -- underscoring that the European Parliament's own spyware-oversight body has been a persistent, cross-vendor surveillance target throughout its mandate. Citizen Lab director Ron Deibert characterized the likely intent as an effort to 'breach parliamentary privilege and find out what was going on in that committee.' The PEGA Committee's final report, which produced recommendations for tighter EU controls on spyware sales and use, saw no binding follow-up action in the European Parliament.
MITRE ATT&CK techniques used in TL-2026-1110
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Defense Evasion
T1407 Download New Code at Runtime; T1629 Impair Defenses; T1631 Process Injection
Collection
T1409 Stored Application Data; T1414 Clipboard Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1533 Data from Local System; T1616 Call Control; T1636 Protected User Data
Discovery
T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1424 Process Discovery; T1426 System Information Discovery
Initial Access
Credential Access
Command and Control
T1521 Encrypted Channel; T1637 Dynamic Resolution
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
Exfiltration
T1639 Exfiltration Over Alternative Protocol; T1646 Exfiltration Over C2 Channel
Affected products and versions in Pegasus Spyware Used Against Former MEP Stelios Kouloglou
- Apple — iPhone (iOS)
Vulnerable versions: iOS 15.1.1; iOS 15.5; iOS 15.6; iOS 16.0.3; iOS versions prior to 16.3.1 (HomeKit) and prior to 16.1 (MessagesBlastDoorService)
Fixed in: iOS 16.3.1 (HomeKit hardening); iOS 16.1 (MessagesBlastDoorService hardening)
Remediation for Pegasus Spyware Used Against Former MEP Stelios Kouloglou
Patches
- Apple iOS 16.3.1 -- HomeKit hardening against NSKeyedArchiver deserialization abuse
- Apple iOS 16.1 -- MessagesBlastDoorService hardening against malicious PNG/MakerNote payloads
Immediate actions
- Update all iOS devices to iOS 16.3.1 or later to close the HomeKit NSKeyedArchiver deserialization vector used in PWNYOURHOME.
- Enable Apple Lockdown Mode on devices belonging to high-risk individuals (politicians, journalists, human-rights defenders, and spyware-oversight committee members).
- Run Mobile Verification Toolkit (MVT) against iOS backups and sysdiagnose logs of at-risk personnel to check for HomeKit and MessagesBlastDoorService compromise indicators.
- Review Apple threat-notification history for all EU parliamentary staff and committee members handling spyware-related oversight work.
Workarounds
- Enable Lockdown Mode, which surfaces real-time notifications of attempted PWNYOURHOME-style exploitation
- Reboot iOS devices regularly, since Pegasus for iOS has historically not persisted across a reboot without re-exploitation
- Restrict or scrutinize HomeKit sharing invitations and Apple ID lookups from unknown accounts where feasible
Longer-term hardening
- Deploy Apple Lockdown Mode by default for personnel involved in spyware oversight, investigative journalism, or opposition politics.
- Establish a rapid forensic-response channel between EU institutions and independent forensic labs (Citizen Lab, Amnesty Security Lab, Access Now) for suspected spyware targeting of officials.
- Advocate for EU-wide export-control and procurement transparency covering NSO Group and other commercial spyware vendors.
- Implement device-replacement and rotation policies for high-risk personnel following any suspected zero-click compromise.
Weaknesses (CWE) in Pegasus Spyware Used Against Former MEP Stelios Kouloglou
CWE-502, CWE-822, CWE-787
Timeline of Pegasus Spyware Used Against Former MEP Stelios Kouloglou
- Maria Epifanova, a Latvia-based exiled Russian journalist, is infected with Pegasus -- the earliest known use of Pegasus against Russian civil society, later linked via a shared HomeKit identifier to the Kouloglou case.
- The related LATENTIMAGE zero-click Pegasus exploit chain is deployed against a single target running an out-of-date iOS 15.1.1, later disclosed by Citizen Lab alongside PWNYOURHOME.
- The European Parliament establishes the PEGA Committee to investigate the scope of Pegasus and equivalent spyware abuse across the EU.
- Stelios Kouloglou becomes a substitute member of the PEGA Committee.
- The related FINDMYPWN zero-click exploit chain infects Centro PRODH director Jorge Santiago Aguirre Espinosa in Mexico, amid truth-commission investigations into the country's 'Dirty War' and the Ayotzinapa case.
- Kouloglou's iPhone (iOS 15.5) is infected with Pegasus via the PWNYOURHOME zero-click exploit while he is hospitalized in Greece; a HomeKit lookup of rauharepo888@gmail.com at 10:16 UTC is followed roughly two minutes later by observable Pegasus network activity.
- Apple issues a wave of state-sponsored-attack threat notifications (through November-December 2022) to multiple victims tied to the 2022 NSO zero-click exploit chain campaign.
- Apple sends Kouloglou his first threat notification, months after the actual October 2022 targeting.
- Kouloglou's iPhone is reinfected with Pegasus via PWNYOURHOME while traveling from Athens to Brussels during final PEGA Committee report negotiations, overlapping with rapporteur Sophie in 't Veld's Greece delegation visit.
- Citizen Lab publishes 'Triple Threat,' publicly disclosing the PWNYOURHOME, FINDMYPWN, and LATENTIMAGE zero-click exploit chains and confirming Apple's iOS 16.3.1 and 16.1 fixes.
- The PEGA Committee's mandate ends and its final report is adopted; Kouloglou's term as substitute member concludes.
- Apple sends Kouloglou a second threat notification.
- Bulgarian MEP Elena Yoncheva's device is found to have been targeted with Pegasus in late October 2023.
- Apple sends Kouloglou a third threat notification.
- Citizen Lab and Access Now publish 'By Whose Authority?', documenting Pegasus targeting of Russian- and Belarusian-speaking exiled journalists and activists in Europe and identifying the same rauharepo888@gmail.com HomeKit identifier used against Kouloglou.
- Citizen Lab publishes 'Espionage Against the European Parliament,' confirming Kouloglou's targeting with high confidence and stating it found no evidence of Greek government involvement.
Sources cited for Pegasus Spyware Used Against Former MEP Stelios Kouloglou
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus
- Triple Threat: NSO Group's Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains
- By Whose Authority? Pegasus targeting of Russian & Belarusian-speaking opposition activists and independent media in Europe
- Former MEP Investigating Spyware Abuses Has Phone Hacked With Pegasus
- European Parliament Member Investigating Spyware Was Hacked With Pegasus
- Someone infected a spyware probe overseer with spyware
- Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds
- Pegasus Spyware Hacked European Parliament Member Investigating Spyware Abuse
- Pegasus Spyware Hacked MEP Serving on European Parliament PEGA Committee
- Former MEP Investigating Spyware Abuses Has Phone Hacked With Pegasus
- NSO zero-click iPhone hack used HomeKit; blocked by Lockdown Mode
- NSO Group escalates spyware tactics with 3 new iPhone zero-click exploit chains
- Zero-Click iPhone Exploit Drops Pegasus Spyware on Exiled Russian Journalist
- NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab
- Pegasus spyware targeted exiled journalists from Russia, Latvia, Belarus, report finds
Threats related to Pegasus Spyware Used Against Former MEP Stelios Kouloglou
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios Kouloglou
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain)
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member
- Pegasus Spyware Re-Targets EU Parliamentarian: Stelios Kouloglou Hacked via PWNYOURHOME Zero-Click Chain While Investigating Spyware Abuse on PEGA Committee
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands
- Predator Spyware: Undocumented iOS Kernel Exploitation Engine (FDGuardNeonRW, PAC Bypass, RWTransfer)
Detection coverage for TL-2026-1110
As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1110 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.