Threat reportThreat IntelligenceTL-2026-1748

NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor

ACTIVE

NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic (TL-2026-1748), also tracked as Pegasus Project, is a informational-severity tracked intrusion set, first published 2026-07-28. It is attributed to NSO Group (Israel) with medium confidence, affects Apple iOS, references 4 CVEs (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657), maps to 22 MITRE ATT&CK techniques (T1404, T1409, T1418), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
INFORMATIONALAssessed severity
CVEs
4Referenced vulnerabilities
Techniques
22MITRE ATT&CK
Actors
1NSO Group
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-1748

Threat ID
TL-2026-1748
Also known as
Pegasus Project
Severity
INFORMATIONAL
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
NSO Group
Attribution confidence
MEDIUM
Nation-state nexus
Israel
Motivation
FINANCIAL
Target sectors
government administration, journalism, civil society, legal, humanrights, diplomatic, ngo
Target regions
Middle East, North America, Latin America, Europe, Africa, Asia
Detection rules
9
Indicators of compromise
27

Malware and tooling in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

Malware and tooling: Chrysaor, FORCEDENTRY, KISMET, Mobile Verification Toolkit (MVT), Trident

How NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic works

An OCCRP/Código Morse/Shomrim investigation, corroborated and published by Citizen Lab, found that NSO Group co-founder Shalev Hulio entered Panama in December 2013 on an Israeli diplomatic passport and told immigration he would stay at the Israeli embassy, days before NSO's Pegasus spyware was sold to the Panamanian government. Citizen Lab researcher John Scott-Railton says the finding raises fresh questions about NSO Group's ties to the Israeli state; Hulio has categorically denied the allegations.

On 2026-07-28, Citizen Lab published an analysis of a joint OCCRP/Código Morse/Shomrim investigation (coordinated under the Forbidden Stories consortium framework that also produced the 2021 Pegasus Project) into Panama migration records from Tocumen International Airport. The records show that Shalev Hulio, co-founder and then-CEO of Israeli offensive-cyber vendor NSO Group (legally operating as Q Cyber Technologies), arrived in Panama City on 3 December 2013 aboard a Copa Airlines flight from the United States, entering on an Israeli diplomatic passport and declaring to immigration officials that he would be staying at the Israeli embassy. The visit preceded a 2012-era Pegasus sale to the government of then-Panamanian President Ricardo Martinelli, whose administration was later engulfed in a wiretapping scandal (investigation opened 2014; Martinelli was acquitted on appeal in 2021).

Citizen Lab researcher John Scott-Railton characterized the diplomatic-passport finding as raising renewed questions about NSO Group's connections to the Israeli state — a recurring theme in NSO reporting given that Israel's Ministry of Defense must approve every Pegasus export license, and NSO's founders (Hulio, Omri Lavie, and Niv Carmi) are alumni of Israeli signals-intelligence Unit 8200 and, in Carmi's case, military intelligence and Mossad. Hulio, through representatives, called the allegations of holding a diplomatic passport and acting as a state representative "entirely false and categorically denied." NSO Group did not respond to requests for comment; Israel's Ministries of Defense and Foreign Affairs both declined to comment.

This is a THREAT_ACTOR/attribution-intelligence item, not a vulnerability or active-campaign disclosure: there is no CVE, exploit, or malware payload tied to this specific finding. Its significance is contextual — it adds a documentary data point (a diplomatic passport and an explicit embassy-residency declaration to a foreign government's immigration authority) to a long-running body of reporting, litigation, and sanctions activity establishing NSO Group as a private-sector offensive-actor (PSOA) whose Pegasus spyware has been repeatedly linked to state and state-enabled surveillance of journalists, human-rights defenders, dissidents, lawyers, and government officials across at least 45 countries (per Citizen Lab's 2018 "Hide and Seek" report) and at least 50 countries (per the 2021 Pegasus Project). NSO Group was added to the U.S. Department of Commerce Entity List in November 2021 for enabling transnational repression; a U.S. federal jury found NSO Group liable under the CFAA and CDAFA in the WhatsApp/Meta civil suit, awarding over $167 million in damages in 2025. Hulio stepped down as NSO Group CEO in 2022. This record documents the actor profile, historical exploit chain (Trident/2016, KISMET/2020, FORCEDENTRY/2021), legal and regulatory history, and the new OSINT data point for downstream correlation and actor-tracking purposes.

MITRE ATT&CK techniques used in TL-2026-1748

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Collection

T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1636.001 Calendar Entries; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages

Discovery

T1418 Software Discovery; T1421 System Network Connections Discovery; T1422 System Network Configuration Discovery; T1422.001 Internet Connection Discovery; T1422.002 Wi-Fi Discovery; T1426 System Information Discovery

Initial Access

T1456 Drive-By Compromise; T1660 Phishing; T1664 Exploitation for Initial Access

Persistence

T1624.001 Broadcast Receivers

Command and Control

T1644 Out of Band Data

persistence

T1645 Compromise Client Software Binary

Execution

T1658 Exploitation for Client Execution

Affected products and versions in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

  • Apple — iOS
    Vulnerable versions: iOS <=9.3.4 (Trident, 2016); iOS 13.5.1-13.7 (KISMET, 2020); iOS <=14.7 (FORCEDENTRY, 2021)
    Fixed in: iOS 9.3.5; iOS 14.8
  • Google — Android
    Vulnerable versions: Various (Pegasus/Chrysaor Android implant, 2016-2017 disclosures)

Remediation for NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

Patches

  • Apple iOS 9.3.5 (2016) — patched the Trident exploit chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657)
  • Apple iOS 14.8 (2021) — patched the FORCEDENTRY exploit chain (CVE-2021-30860)

Immediate actions

  • Apply Apple iOS 14.8+ and current security updates to close the FORCEDENTRY (CVE-2021-30860) zero-click iMessage vector historically used to deliver Pegasus
  • Enable Apple Lockdown Mode on devices belonging to journalists, human-rights defenders, lawyers, and government officials assessed as high-risk targets
  • Run Amnesty International's Mobile Verification Toolkit (MVT) against at-risk iOS/Android devices to check for known Pegasus forensic artifacts

Workarounds

  • Periodic device reboots to disrupt non-persistent Pegasus implants
  • Disable iMessage/FaceTime for high-risk individuals to reduce zero-click attack surface

Longer-term hardening

  • Track U.S. Commerce Department Entity List and comparable export-control designations before any procurement, partnership, or data-sharing decision involving commercial spyware vendors
  • Require multi-source corroboration before treating vendor-state-nexus claims as confirmed attribution; this finding raises questions but does not itself establish formal state control of NSO Group
  • Monitor ongoing civil litigation (WhatsApp/Meta v. NSO Group, prior Apple v. NSO Group) for precedent affecting commercial spyware vendor accountability

CVEs associated with NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

CVE-2016-4655, CVE-2016-4656, CVE-2016-4657, CVE-2021-30860

Weaknesses (CWE) in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

CWE-190, CWE-787, CWE-119

Timeline of NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

  • NSO Group founded in Israel by Niv Carmi, Omri Lavie, and Shalev Hulio; the company name derives from the founders' initials. Carmi is a veteran of Israeli military intelligence and Mossad; Hulio and Lavie are Unit 8200 alumni.
  • First iteration of the Pegasus mobile spyware is finalized by NSO Group.
  • NSO Group sells Pegasus to the government of Panama under President Ricardo Martinelli.
  • Shalev Hulio arrives at Panama City's Tocumen International Airport on a Copa Airlines flight from the U.S., entering Panama on an Israeli diplomatic passport and telling immigration officials he would be staying at the Israeli embassy, per Panama migration records reviewed by OCCRP/Código Morse/Shomrim.
  • Panamanian authorities open an official investigation into a wiretapping scandal linked to the Martinelli administration's use of Pegasus.
  • Citizen Lab and Lookout disclose the Trident exploit chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) used by NSO Group's Pegasus against UAE human-rights defender Ahmed Mansoor, prompting Apple's iOS 9.3.5 emergency patch.
  • NSO Group founders Hulio and Lavie, backed by European private-equity fund Novalpina Capital, complete a majority buyout of NSO Group valuing the company at roughly $1 billion.
  • WhatsApp identifies that NSO Group exploited its servers to install Pegasus on the mobile devices of more than 1,400 users between April and May 2019, later forming the basis of Meta/WhatsApp's civil suit.
  • The Pegasus Project — a Forbidden Stories-coordinated consortium of 80+ journalists across 17 outlets, working with Amnesty International's Security Lab — publishes analysis of a leaked list of 50,000+ phone numbers selected by NSO clients since 2016, confirming Pegasus infection or attempted infection in 37 of 67 forensically examined phones.
  • Citizen Lab discloses the FORCEDENTRY zero-click iMessage exploit (CVE-2021-30860), an integer-overflow vulnerability in Apple CoreGraphics that bypassed BlastDoor to deliver Pegasus; Apple ships an emergency iOS 14.8 patch the same day.
  • The U.S. Department of Commerce adds NSO Group and Candiru to its Entity List for developing and supplying spyware used by foreign governments to conduct transnational repression against journalists, activists, and officials.
  • Shalev Hulio steps down as CEO of NSO Group.
  • U.S. District Judge Phyllis J. Hamilton rules NSO Group liable for violating the Computer Fraud and Abuse Act (CFAA) and California's CDAFA, and for breaching WhatsApp's terms of service, in the Meta/WhatsApp civil suit.
  • A federal jury awards Meta/WhatsApp $167,254,000 in punitive damages and $444,719 in compensatory damages against NSO Group — the first jury verdict against a commercial spyware company in U.S. court.
  • Citizen Lab publishes analysis of the OCCRP/Código Morse/Shomrim investigation into Hulio's 2013 diplomatic-passport entry to Panama; researcher John Scott-Railton says the finding raises questions about NSO Group's ties to the Israeli state, while Hulio categorically denies the allegations and NSO Group and Israeli ministries decline to comment.

Sources cited for NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic

Detection coverage for TL-2026-1748

As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1748 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats