Threat reportThreat IntelligenceTL-2026-1748
NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic (TL-2026-1748), also tracked as Pegasus Project, is a informational-severity tracked intrusion set, first published 2026-07-28. It is attributed to NSO Group (Israel) with medium confidence, affects Apple iOS, references 4 CVEs (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657), maps to 22 MITRE ATT&CK techniques (T1404, T1409, T1418), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- INFORMATIONALAssessed severity
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 22MITRE ATT&CK
- Actors
- 1NSO Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1748
- Threat ID
- TL-2026-1748
- Also known as
- Pegasus Project
- Severity
- INFORMATIONAL
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- NSO Group
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Israel
- Motivation
- FINANCIAL
- Target sectors
- government administration, journalism, civil society, legal, humanrights, diplomatic, ngo
- Target regions
- Middle East, North America, Latin America, Europe, Africa, Asia
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
Malware and tooling: Chrysaor, FORCEDENTRY, KISMET, Mobile Verification Toolkit (MVT), Trident
How NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic works
An OCCRP/Código Morse/Shomrim investigation, corroborated and published by Citizen Lab, found that NSO Group co-founder Shalev Hulio entered Panama in December 2013 on an Israeli diplomatic passport and told immigration he would stay at the Israeli embassy, days before NSO's Pegasus spyware was sold to the Panamanian government. Citizen Lab researcher John Scott-Railton says the finding raises fresh questions about NSO Group's ties to the Israeli state; Hulio has categorically denied the allegations.
On 2026-07-28, Citizen Lab published an analysis of a joint OCCRP/Código Morse/Shomrim investigation (coordinated under the Forbidden Stories consortium framework that also produced the 2021 Pegasus Project) into Panama migration records from Tocumen International Airport. The records show that Shalev Hulio, co-founder and then-CEO of Israeli offensive-cyber vendor NSO Group (legally operating as Q Cyber Technologies), arrived in Panama City on 3 December 2013 aboard a Copa Airlines flight from the United States, entering on an Israeli diplomatic passport and declaring to immigration officials that he would be staying at the Israeli embassy. The visit preceded a 2012-era Pegasus sale to the government of then-Panamanian President Ricardo Martinelli, whose administration was later engulfed in a wiretapping scandal (investigation opened 2014; Martinelli was acquitted on appeal in 2021).
Citizen Lab researcher John Scott-Railton characterized the diplomatic-passport finding as raising renewed questions about NSO Group's connections to the Israeli state — a recurring theme in NSO reporting given that Israel's Ministry of Defense must approve every Pegasus export license, and NSO's founders (Hulio, Omri Lavie, and Niv Carmi) are alumni of Israeli signals-intelligence Unit 8200 and, in Carmi's case, military intelligence and Mossad. Hulio, through representatives, called the allegations of holding a diplomatic passport and acting as a state representative "entirely false and categorically denied." NSO Group did not respond to requests for comment; Israel's Ministries of Defense and Foreign Affairs both declined to comment.
This is a THREAT_ACTOR/attribution-intelligence item, not a vulnerability or active-campaign disclosure: there is no CVE, exploit, or malware payload tied to this specific finding. Its significance is contextual — it adds a documentary data point (a diplomatic passport and an explicit embassy-residency declaration to a foreign government's immigration authority) to a long-running body of reporting, litigation, and sanctions activity establishing NSO Group as a private-sector offensive-actor (PSOA) whose Pegasus spyware has been repeatedly linked to state and state-enabled surveillance of journalists, human-rights defenders, dissidents, lawyers, and government officials across at least 45 countries (per Citizen Lab's 2018 "Hide and Seek" report) and at least 50 countries (per the 2021 Pegasus Project). NSO Group was added to the U.S. Department of Commerce Entity List in November 2021 for enabling transnational repression; a U.S. federal jury found NSO Group liable under the CFAA and CDAFA in the WhatsApp/Meta civil suit, awarding over $167 million in damages in 2025. Hulio stepped down as NSO Group CEO in 2022. This record documents the actor profile, historical exploit chain (Trident/2016, KISMET/2020, FORCEDENTRY/2021), legal and regulatory history, and the new OSINT data point for downstream correlation and actor-tracking purposes.
MITRE ATT&CK techniques used in TL-2026-1748
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Collection
T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1636.001 Calendar Entries; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages
Discovery
T1418 Software Discovery; T1421 System Network Connections Discovery; T1422 System Network Configuration Discovery; T1422.001 Internet Connection Discovery; T1422.002 Wi-Fi Discovery; T1426 System Information Discovery
Initial Access
T1456 Drive-By Compromise; T1660 Phishing; T1664 Exploitation for Initial Access
Persistence
Command and Control
persistence
T1645 Compromise Client Software Binary
Execution
Affected products and versions in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
Remediation for NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
Patches
- Apple iOS 9.3.5 (2016) — patched the Trident exploit chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657)
- Apple iOS 14.8 (2021) — patched the FORCEDENTRY exploit chain (CVE-2021-30860)
Immediate actions
- Apply Apple iOS 14.8+ and current security updates to close the FORCEDENTRY (CVE-2021-30860) zero-click iMessage vector historically used to deliver Pegasus
- Enable Apple Lockdown Mode on devices belonging to journalists, human-rights defenders, lawyers, and government officials assessed as high-risk targets
- Run Amnesty International's Mobile Verification Toolkit (MVT) against at-risk iOS/Android devices to check for known Pegasus forensic artifacts
Workarounds
- Periodic device reboots to disrupt non-persistent Pegasus implants
- Disable iMessage/FaceTime for high-risk individuals to reduce zero-click attack surface
Longer-term hardening
- Track U.S. Commerce Department Entity List and comparable export-control designations before any procurement, partnership, or data-sharing decision involving commercial spyware vendors
- Require multi-source corroboration before treating vendor-state-nexus claims as confirmed attribution; this finding raises questions but does not itself establish formal state control of NSO Group
- Monitor ongoing civil litigation (WhatsApp/Meta v. NSO Group, prior Apple v. NSO Group) for precedent affecting commercial spyware vendor accountability
CVEs associated with NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
Weaknesses (CWE) in NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
Timeline of NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
- NSO Group founded in Israel by Niv Carmi, Omri Lavie, and Shalev Hulio; the company name derives from the founders' initials. Carmi is a veteran of Israeli military intelligence and Mossad; Hulio and Lavie are Unit 8200 alumni.
- First iteration of the Pegasus mobile spyware is finalized by NSO Group.
- NSO Group sells Pegasus to the government of Panama under President Ricardo Martinelli.
- Shalev Hulio arrives at Panama City's Tocumen International Airport on a Copa Airlines flight from the U.S., entering Panama on an Israeli diplomatic passport and telling immigration officials he would be staying at the Israeli embassy, per Panama migration records reviewed by OCCRP/Código Morse/Shomrim.
- Panamanian authorities open an official investigation into a wiretapping scandal linked to the Martinelli administration's use of Pegasus.
- Citizen Lab and Lookout disclose the Trident exploit chain (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) used by NSO Group's Pegasus against UAE human-rights defender Ahmed Mansoor, prompting Apple's iOS 9.3.5 emergency patch.
- NSO Group founders Hulio and Lavie, backed by European private-equity fund Novalpina Capital, complete a majority buyout of NSO Group valuing the company at roughly $1 billion.
- WhatsApp identifies that NSO Group exploited its servers to install Pegasus on the mobile devices of more than 1,400 users between April and May 2019, later forming the basis of Meta/WhatsApp's civil suit.
- The Pegasus Project — a Forbidden Stories-coordinated consortium of 80+ journalists across 17 outlets, working with Amnesty International's Security Lab — publishes analysis of a leaked list of 50,000+ phone numbers selected by NSO clients since 2016, confirming Pegasus infection or attempted infection in 37 of 67 forensically examined phones.
- Citizen Lab discloses the FORCEDENTRY zero-click iMessage exploit (CVE-2021-30860), an integer-overflow vulnerability in Apple CoreGraphics that bypassed BlastDoor to deliver Pegasus; Apple ships an emergency iOS 14.8 patch the same day.
- The U.S. Department of Commerce adds NSO Group and Candiru to its Entity List for developing and supplying spyware used by foreign governments to conduct transnational repression against journalists, activists, and officials.
- Shalev Hulio steps down as CEO of NSO Group.
- U.S. District Judge Phyllis J. Hamilton rules NSO Group liable for violating the Computer Fraud and Abuse Act (CFAA) and California's CDAFA, and for breaching WhatsApp's terms of service, in the Meta/WhatsApp civil suit.
- A federal jury awards Meta/WhatsApp $167,254,000 in punitive damages and $444,719 in compensatory damages against NSO Group — the first jury verdict against a commercial spyware company in U.S. court.
- Citizen Lab publishes analysis of the OCCRP/Código Morse/Shomrim investigation into Hulio's 2013 diplomatic-passport entry to Panama; researcher John Scott-Railton says the finding raises questions about NSO Group's ties to the Israeli state, while Hulio categorically denies the allegations and NSO Group and Israeli ministries decline to comment.
Sources cited for NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic
- Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport
- Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport (OCCRP)
- FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild
- Hide and Seek: Tracking NSO Group's Pegasus Spyware to Operations in 45 Countries
- The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender
- Forensic Methodology Report: How to Catch NSO Group's Pegasus
- Pegasus for iOS, Software S0289
- Pegasus for Android, Software S0316
- US Sanctions Pegasus-maker NSO Group and 3 Others For Selling Spyware
- US Judge Rules Against NSO Group in WhatsApp Pegasus Spyware Case
- NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware
- Apple Drops Spyware Case Against NSO Group, Citing Risk of Threat Intelligence Exposure
- 'Somebody has to do the dirty work': NSO founders defend the spyware they built
- AmnestyTech Investigations: NSO Group Pegasus IOCs (2021-07-18_nso)
Detection coverage for TL-2026-1748
As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1748 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.