NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor — Threadlinqs Intelligence
As of 2026-07-28, NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor is a informational-severity threat intel threat attributed to NSO Group (Israel), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1748 · Severity: INFORMATIONAL · Status: ACTIVE · Category: THREAT_INTEL
Attribution: NSO Group · Israel · FINANCIAL
An OCCRP/Código Morse/Shomrim investigation, corroborated and published by Citizen Lab, found that NSO Group co-founder Shalev Hulio entered Panama in December 2013 on an Israeli diplomatic passport
On 2026-07-28, Citizen Lab published an analysis of a joint OCCRP/Código Morse/Shomrim investigation (coordinated under the Forbidden Stories consortium framework that also produced the 2021 Pegasus Project) into Panama migration records from Tocumen International Airport. The records show that Shalev Hulio, co-founder and then-CEO of Israeli offensive-cyber vendor NSO Group (legally operating as Q Cyber Technologies), arrived in Panama City on 3 December 2013 aboard a Copa Airlines flight from the United States, entering on an Israeli diplomatic passport and declaring to immigration officials that he would be staying at the Israeli embassy. The visit preceded a 2012-era Pegasus sale to the government of then-Panamanian President Ricardo Martinelli, whose administration was later engulfed in a wiretapping scandal (investigation opened 2014; Martinelli was acquitted on appeal in 2021).
Citizen Lab researcher John Scott-Railton characterized the diplomatic-passport finding as raising renewed questions about NSO Group's connections to the Israeli state — a recurring theme in NSO reporting given that Israel's Ministry of Defense must approve every Pegasus export license, and NSO's founders (Hulio, Omri Lavie, and Niv Carmi) are alumni of Israeli signals-intelligence Unit 8200 and, in Carmi's case, military intelligence and Mossad. Hulio, through representatives, called the allegations of holding a diplomatic passport and acting as a state representative "entirely false and categorically denied." NSO Group did not respond to requests for comment; Israel's Ministries of Defense and Foreign Affairs both declined to comment.
This is a THREAT_ACTOR/attribution-intelligence item, not a vulnerability or active-campaign disclosure: there is no CVE, exploit, or malware payload tied to this specific finding. Its significance is contextual — it adds a documentary data point (a diplomatic passport and an explicit embassy-residency declaration to a foreign government's immigration authority) to a long-running body of reporting, litigation, and sanctions activity establishing NSO Group as a private-sector offensive-actor (PSOA) whose Pegasus spyware has been repeatedly linked to state and state-enabled surveillance of journalists, human-rights defenders, dissidents, lawyers, and government officials across at least 45 countries (per Citizen Lab's 2018 "Hide and Seek" report) and at least 50 countries (per the 2021 Pegasus Project). NSO Group was added to the U.S. Department of Commerce Entity List in November 2021 for enabling transnational repression; a U.S. federal jury found NSO Group liable under the CFAA and CDAFA in the WhatsApp/Meta civil suit, awarding over $167 million in damages in 2025. Hulio stepped down as NSO Group CEO in 2022. This record documents the actor profile, historical exploit chain (Trident/2016, KISMET/2020, FORCEDENTRY/2021), legal and regulatory history, and the new OSINT data point for downstream correlation and actor-tracking purposes.
Weaknesses (CWE)
CWE-190, CWE-787, CWE-119
Target sectors: government administration, journalism, civil society, legal, humanrights, diplomatic, ngo
Target regions: Middle East, North America, Latin America, Europe, Africa, Asia
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFORMATIONAL, threat intelligence, cybersecurity, CVE-2016-4655, CVE-2016-4656, CVE-2016-4657, CVE-2021-30860, T1456, T1664, T1660, T1658, T1624.001, T1404, T1645, T1418, T1422, T1422.001