Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee

Pegasus Spyware Used Against Former MEP Stelios Kouloglou (TL-2026-1110), also tracked as PWNYOURHOME, is a critical-severity malware campaign, first published 2026-07-05. It has no confirmed attribution, affects Apple iPhone (iOS), maps to 25 MITRE ATT&CK techniques (T1404, T1407, T1409), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1110

Threat ID
TL-2026-1110
Also known as
PWNYOURHOME, Espionage Against the European Parliament
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
2026-07-05
Last reviewed
2026-07-05
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, legislative, ngo, news - media, civil society
Target regions
Europe, greece, belgium, latvia, lithuania, poland, spain, mexico
Detection rules
9
Indicators of compromise
27

Malware and tooling in Pegasus Spyware Used Against Former MEP Stelios Kouloglou

Malware and tooling: Chrysaor, Predator, FINDMYPWN, LATENTIMAGE, PWNYOURHOME, Pegasus Anonymizing Transmission Network (PATN)

Citizen Lab forensic analysis confirmed with high confidence that former European Parliament member Stelios Kouloglou, a substitute member of the PEGA Committee investigating spyware abuse, was infected with NSO Group's Pegasus spyware via the PWNYOURHOME zero-click exploit chain on October 21, 2022 and again on March 6-7, 2023. Citizen Lab found no evidence of Greek government involvement but identified an attacker-controlled HomeKit-linked email address that overlaps with a prior Pegasus campaign targeting Russian- and Belarusian-speaking exiled journalists and activists across Europe.

How Pegasus Spyware Used Against Former MEP Stelios Kouloglou works

Stelios Kouloglou, a Greek investigative journalist and Member of the European Parliament (2015-2024) who served as a substitute member of the European Parliament's PEGA Committee investigating spyware abuse (March 24, 2022 - July 18, 2023), was targeted twice with NSO Group's Pegasus mercenary spyware while the committee was actively drafting and negotiating its findings on EU spyware abuse.

The first infection occurred on October 21, 2022 while Kouloglou was hospitalized in Greece, ten days before he personally joined a Cyprus-Greece PEGA delegation trip and during the committee's initial report drafting. The second infection occurred March 6-7, 2023 while he traveled from Athens to Brussels during final PEGA report negotiations, overlapping with rapporteur Sophie in 't Veld's delegation visit to Greece. Both infections used the PWNYOURHOME zero-click exploit chain: a specially crafted NSKeyedArchive delivered to the iPhone's HomeKit daemon (homed), triggered via a lookup of the attacker-controlled address rauharepo888@gmail.com (recorded at 2022-10-21 10:16 UTC), followed roughly two minutes later by malicious content landing in MessagesBlastDoorService and observable Pegasus mobile-data network activity. The target device ran iOS 15.5 (build 19F77) at the time of both infections.

PWNYOURHOME was one of three novel NSO zero-click exploit chains publicly disclosed by Citizen Lab in its April 2023 'Triple Threat' report, alongside FINDMYPWN (which abuses the Find My daemon fmfd before pivoting into MessagesBlastDoorService, used against Mexican human-rights defenders at Centro PRODH in mid-2022) and LATENTIMAGE (a low-trace single-case chain observed in January 2022 against an out-of-date iOS 15.1.1 device). All three chains circumvent Apple's Pointer Authentication Code (PAC) mitigations by repurposing known-offset signed pointers already present in the iOS shared cache, allowing code execution despite modern exploit mitigations. Apple addressed the HomeKit vector in iOS 16.3.1 and the MessagesBlastDoorService vector earlier, around iOS 16.1.

Citizen Lab's attribution assessment states explicitly that it is 'not attributing these infections to a particular government at this time' and found 'no indications that the Greek Government is responsible' and no indication Greece has ever been an NSO Group customer. However, the rauharepo888@gmail.com HomeKit identifier used against Kouloglou reappears as a redacted Apple ID in Citizen Lab and Access Now's May 2024 report 'By Whose Authority?' documenting Pegasus targeting of at least seven Russian- and Belarusian-speaking exiled journalists and opposition activists across Latvia, Lithuania, and Poland between 2020 and 2023 (including Maria Epifanova, Natalya Radina, and Evgeniy Erlich), suggesting a single NSO customer operating with multi-country licensing across EU jurisdictions. Kouloglou received Apple threat notifications on March 2, 2023, August 29, 2023, and April 10, 2024 -- each arriving months after the actual targeting, consistent with Apple's standard batch-notification delay.

Kouloglou is the first publicly identified PEGA Committee member confirmed compromised while actively serving on the inquiry into spyware abuses, but not the only one: PEGA Committee Chair Nathalie Loiseau, Vice-Chair Diana Riba, substitute member Jordi Sole, and member Carles Puigdemont were all separately confirmed as Pegasus targets (the latter three tied to the 'CatalanGate' campaign against Catalan independence figures), Bulgarian MEP Elena Yoncheva was targeted with Pegasus in late October 2023, and German MEP Daniel Freund disclosed targeting with Candiru spyware in May 2024. The case sits alongside Greece's own domestic 'Predatorgate' scandal, in which Intellexa's Predator spyware (a different vendor and platform) was used to surveil PASOK leader and MEP Nikos Androulakis and journalist Thanasis Koukakis -- underscoring that the European Parliament's own spyware-oversight body has been a persistent, cross-vendor surveillance target throughout its mandate. Citizen Lab director Ron Deibert characterized the likely intent as an effort to 'breach parliamentary privilege and find out what was going on in that committee.' The PEGA Committee's final report, which produced recommendations for tighter EU controls on spyware sales and use, saw no binding follow-up action in the European Parliament.

MITRE ATT&CK techniques used in TL-2026-1110

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Defense Evasion

T1407 Download New Code at Runtime; T1629 Impair Defenses; T1631 Process Injection

Collection

T1409 Stored Application Data; T1414 Clipboard Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1533 Data from Local System; T1616 Call Control; T1636 Protected User Data

Discovery

T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1424 Process Discovery; T1426 System Information Discovery

Initial Access

T1456 Drive-By Compromise

Credential Access

T1517 Access Notifications

Command and Control

T1521 Encrypted Channel; T1637 Dynamic Resolution

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Exfiltration

T1639 Exfiltration Over Alternative Protocol; T1646 Exfiltration Over C2 Channel

Affected products and versions in Pegasus Spyware Used Against Former MEP Stelios Kouloglou

  • Apple — iPhone (iOS)
    Vulnerable versions: iOS 15.1.1; iOS 15.5; iOS 15.6; iOS 16.0.3; iOS versions prior to 16.3.1 (HomeKit) and prior to 16.1 (MessagesBlastDoorService)
    Fixed in: iOS 16.3.1 (HomeKit hardening); iOS 16.1 (MessagesBlastDoorService hardening)

Remediation for Pegasus Spyware Used Against Former MEP Stelios Kouloglou

Patches

  • Apple iOS 16.3.1 -- HomeKit hardening against NSKeyedArchiver deserialization abuse
  • Apple iOS 16.1 -- MessagesBlastDoorService hardening against malicious PNG/MakerNote payloads

Immediate actions

  • Update all iOS devices to iOS 16.3.1 or later to close the HomeKit NSKeyedArchiver deserialization vector used in PWNYOURHOME.
  • Enable Apple Lockdown Mode on devices belonging to high-risk individuals (politicians, journalists, human-rights defenders, and spyware-oversight committee members).
  • Run Mobile Verification Toolkit (MVT) against iOS backups and sysdiagnose logs of at-risk personnel to check for HomeKit and MessagesBlastDoorService compromise indicators.
  • Review Apple threat-notification history for all EU parliamentary staff and committee members handling spyware-related oversight work.

Workarounds

  • Enable Lockdown Mode, which surfaces real-time notifications of attempted PWNYOURHOME-style exploitation
  • Reboot iOS devices regularly, since Pegasus for iOS has historically not persisted across a reboot without re-exploitation
  • Restrict or scrutinize HomeKit sharing invitations and Apple ID lookups from unknown accounts where feasible

Longer-term hardening

  • Deploy Apple Lockdown Mode by default for personnel involved in spyware oversight, investigative journalism, or opposition politics.
  • Establish a rapid forensic-response channel between EU institutions and independent forensic labs (Citizen Lab, Amnesty Security Lab, Access Now) for suspected spyware targeting of officials.
  • Advocate for EU-wide export-control and procurement transparency covering NSO Group and other commercial spyware vendors.
  • Implement device-replacement and rotation policies for high-risk personnel following any suspected zero-click compromise.

Weaknesses (CWE) in Pegasus Spyware Used Against Former MEP Stelios Kouloglou

CWE-502, CWE-822, CWE-787

Timeline of Pegasus Spyware Used Against Former MEP Stelios Kouloglou

  • Maria Epifanova, a Latvia-based exiled Russian journalist, is infected with Pegasus -- the earliest known use of Pegasus against Russian civil society, later linked via a shared HomeKit identifier to the Kouloglou case.
  • The related LATENTIMAGE zero-click Pegasus exploit chain is deployed against a single target running an out-of-date iOS 15.1.1, later disclosed by Citizen Lab alongside PWNYOURHOME.
  • The European Parliament establishes the PEGA Committee to investigate the scope of Pegasus and equivalent spyware abuse across the EU.
  • Stelios Kouloglou becomes a substitute member of the PEGA Committee.
  • The related FINDMYPWN zero-click exploit chain infects Centro PRODH director Jorge Santiago Aguirre Espinosa in Mexico, amid truth-commission investigations into the country's 'Dirty War' and the Ayotzinapa case.
  • Kouloglou's iPhone (iOS 15.5) is infected with Pegasus via the PWNYOURHOME zero-click exploit while he is hospitalized in Greece; a HomeKit lookup of rauharepo888@gmail.com at 10:16 UTC is followed roughly two minutes later by observable Pegasus network activity.
  • Apple issues a wave of state-sponsored-attack threat notifications (through November-December 2022) to multiple victims tied to the 2022 NSO zero-click exploit chain campaign.
  • Apple sends Kouloglou his first threat notification, months after the actual October 2022 targeting.
  • Kouloglou's iPhone is reinfected with Pegasus via PWNYOURHOME while traveling from Athens to Brussels during final PEGA Committee report negotiations, overlapping with rapporteur Sophie in 't Veld's Greece delegation visit.
  • Citizen Lab publishes 'Triple Threat,' publicly disclosing the PWNYOURHOME, FINDMYPWN, and LATENTIMAGE zero-click exploit chains and confirming Apple's iOS 16.3.1 and 16.1 fixes.
  • The PEGA Committee's mandate ends and its final report is adopted; Kouloglou's term as substitute member concludes.
  • Apple sends Kouloglou a second threat notification.
  • Bulgarian MEP Elena Yoncheva's device is found to have been targeted with Pegasus in late October 2023.
  • Apple sends Kouloglou a third threat notification.
  • Citizen Lab and Access Now publish 'By Whose Authority?', documenting Pegasus targeting of Russian- and Belarusian-speaking exiled journalists and activists in Europe and identifying the same rauharepo888@gmail.com HomeKit identifier used against Kouloglou.
  • Citizen Lab publishes 'Espionage Against the European Parliament,' confirming Kouloglou's targeting with high confidence and stating it found no evidence of Greek government involvement.

Sources cited for Pegasus Spyware Used Against Former MEP Stelios Kouloglou

Threats related to Pegasus Spyware Used Against Former MEP Stelios Kouloglou

Detection coverage for TL-2026-1110

As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1110 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats