Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee — Threadlinqs Intelligence
As of 2026-07-05, Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee is a critical-severity malware threat attributed to Unidentified NSO Group Pegasus Customer, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1110 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: Unidentified NSO Group Pegasus Customer · ESPIONAGE
Citizen Lab forensic analysis confirmed with high confidence that former European Parliament member Stelios Kouloglou, a substitute member of the PEGA Committee investigating spyware abuse, was
Stelios Kouloglou, a Greek investigative journalist and Member of the European Parliament (2015-2024) who served as a substitute member of the European Parliament's PEGA Committee investigating spyware abuse (March 24, 2022 - July 18, 2023), was targeted twice with NSO Group's Pegasus mercenary spyware while the committee was actively drafting and negotiating its findings on EU spyware abuse.
The first infection occurred on October 21, 2022 while Kouloglou was hospitalized in Greece, ten days before he personally joined a Cyprus-Greece PEGA delegation trip and during the committee's initial report drafting. The second infection occurred March 6-7, 2023 while he traveled from Athens to Brussels during final PEGA report negotiations, overlapping with rapporteur Sophie in 't Veld's delegation visit to Greece. Both infections used the PWNYOURHOME zero-click exploit chain: a specially crafted NSKeyedArchive delivered to the iPhone's HomeKit daemon (homed), triggered via a lookup of the attacker-controlled address rauharepo888@gmail.com (recorded at 2022-10-21 10:16 UTC), followed roughly two minutes later by malicious content landing in MessagesBlastDoorService and observable Pegasus mobile-data network activity. The target device ran iOS 15.5 (build 19F77) at the time of both infections.
PWNYOURHOME was one of three novel NSO zero-click exploit chains publicly disclosed by Citizen Lab in its April 2023 'Triple Threat' report, alongside FINDMYPWN (which abuses the Find My daemon fmfd before pivoting into MessagesBlastDoorService, used against Mexican human-rights defenders at Centro PRODH in mid-2022) and LATENTIMAGE (a low-trace single-case chain observed in January 2022 against an out-of-date iOS 15.1.1 device). All three chains circumvent Apple's Pointer Authentication Code (PAC) mitigations by repurposing known-offset signed pointers already present in the iOS shared cache, allowing code execution despite modern exploit mitigations. Apple addressed the HomeKit vector in iOS 16.3.1 and the MessagesBlastDoorService vector earlier, around iOS 16.1.
Citizen Lab's attribution assessment states explicitly that it is 'not attributing these infections to a particular government at this time' and found 'no indications that the Greek Government is responsible' and no indication Greece has ever been an NSO Group customer. However, the rauharepo888@gmail.com HomeKit identifier used against Kouloglou reappears as a redacted Apple ID in Citizen Lab and Access Now's May 2024 report 'By Whose Authority?' documenting Pegasus targeting of at least seven Russian- and Belarusian-speaking exiled journalists and opposition activists across Latvia, Lithuania, and Poland between 2020 and 2023 (including Maria Epifanova, Natalya Radina, and Evgeniy Erlich), suggesting a single NSO customer operating with multi-country licensing across EU jurisdictions. Kouloglou received Apple threat notifications on March 2, 2023, August 29, 2023, and April 10, 2024 -- each arriving months after the actual targeting, consistent with Apple's standard batch-notification delay.
Kouloglou is the first publicly identified PEGA Committee member confirmed compromised while actively serving on the inquiry into spyware abuses, but not the only one: PEGA Committee Chair Nathalie Loiseau, Vice-Chair Diana Riba, substitute member Jordi Sole, and member Carles Puigdemont were all separately confirmed as Pegasus targets (the latter three tied to the 'CatalanGate' campaign against Catalan independence figures), Bulgarian MEP Elena Yoncheva was targeted with Pegasus in late October 2023, and German MEP Daniel Freund disclosed targeting with Candiru spyware in May 2024. The case sits alongside Greece's own domestic 'Predatorgate' scandal, in which Intellexa's Predator spyware (a different vendor and platform) was used to surveil PASOK leader and MEP Nikos Androulakis and journalist Thanasis Koukakis -- underscoring that the European Parliament's own spyware-oversight body has been
Weaknesses (CWE)
CWE-502, CWE-822, CWE-787
Target sectors: government administration, legislative, ngo, news - media, civil society
Target regions: Europe, greece, belgium, latvia, lithuania, poland, spain, mexico
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1583, T1588, T1585, T1456, T1404, T1407, T1631, T1629, T1517, T1426