Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member
Pegasus Spyware Used to Hack Phone of Former MEP Stelios (TL-2026-2324), also tracked as PWNYOURHOME, is a high-severity malware campaign, first published 2026-09-04. It has no confirmed attribution, affects Apple iOS, maps to 14 MITRE ATT&CK techniques (T1404, T1409, T1421), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-2324
- Threat ID
- TL-2026-2324
- Also known as
- PWNYOURHOME
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-04
- Last reviewed
- 2026-09-04
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, news - media, civil society
- Target regions
- Europe, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Pegasus Spyware Used to Hack Phone of Former MEP Stelios
Malware and tooling: Chrysaor, NSO Group Pegasus for iOS
Citizen Lab forensic analysis, published by Access Now on July 6, 2026, confirmed that the iPhone of Stelios Kouloglou -- a Greek journalist and former MEP who served on the European Parliament's PEGA Committee investigating spyware abuses -- was infected with NSO Group's Pegasus spyware on October 21, 2022 and again on March 6-7, 2023 via the zero-click PWNYOURHOME exploit chain. The attacker-controlled Apple ID used against Kouloglou (rauharepo888@gmail.com) was previously linked to the 2024 Access Now/Citizen Lab investigation into the hacking of exiled Russian and Belarusian journalists, though Citizen Lab found no evidence implicating the Greek, Russian, or Belarusian governments.
How Pegasus Spyware Used to Hack Phone of Former MEP Stelios works
On July 3, 2026, the Citizen Lab published forensic findings, amplified by an Access Now press release on July 6, 2026, showing that the iPhone of Stelios Kouloglou -- a Greek investigative journalist and former Member of the European Parliament who sat as a substitute member on Parliament's PEGA Committee of Inquiry into Pegasus and equivalent spyware -- was infected twice with NSO Group's Pegasus spyware. The first infection occurred on October 21, 2022 at 10:16 UTC while Kouloglou was hospitalized in Greece; that same day he was visited by fellow Greek journalist Thanasis Koukakis, who one month earlier had testified before the PEGA Committee about his own targeting with Intellexa's Predator spyware. A second infection window ran from March 6 to March 7, 2023 while Kouloglou was in Brussels for parliamentary business. Apple sent Kouloglou threat notifications on March 2, 2023, August 29, 2023, and April 10, 2024.
Both infections were delivered through PWNYOURHOME, a two-stage zero-click exploit chain that NSO Group began deploying against iOS 15 and 16 in October 2022. Citizen Lab's forensic analysis found a lookup for a HomeKit-associated email address, rauharepo888@gmail.com, immediately preceding the point at which a Pegasus process began using the device's mobile data connection -- consistent with the exploit's documented two-phase mechanism: a specially crafted NSKeyedArchive object is delivered to crash Apple's HomeKit daemon, and malicious content is then delivered to crash MessagesBlastDoorService, iMessage's sandboxed content-parsing service, achieving code execution without any interaction from the victim. Kouloglou's device was running iOS 15.5 (build 19F77) during both infection periods. Citizen Lab shared forensic artifacts on the HomeKit component with Apple in January 2023, and Apple shipped a fix in iOS 16.3.1; the MessagesBlastDoorService component had already been mitigated around iOS 16.1. Citizen Lab first disclosed PWNYOURHOME publicly, alongside two sibling zero-click chains (FINDMYPWN and LATENTIMAGE), in its April 18, 2023 'Triple Threat' report.
The forensic link that elevates this case beyond an isolated infection is infrastructure reuse: the same Apple ID, rauharepo888@gmail.com, appears as one of the redacted attacker identifiers in Access Now and Citizen Lab's May 30, 2024 report 'Civil Society in Exile: Pegasus,' which documented at least seven Russian- and Belarusian-speaking journalists and civil society members living in exile across Latvia, Lithuania, and Poland who were targeted with Pegasus between August 2020 and January 2023 -- including Novaya Gazeta Europe CEO Maria Epifanova (infected August 2020, the earliest known Pegasus use against Russian civil society), Israeli-Russian journalist Evgeny Erlikh (infected November 28-29, 2022), Latvian journalist Evgeniy Pavlov (targeted November 2022 and April 2023), and Belarusian opposition figure Andrei Sannikov. Citizen Lab explicitly states it has no evidence implicating the Greek, Russian, or Belarusian governments, but notes that because Kouloglou was infected in both Greece and Belgium, the responsible NSO Group customer likely held a license permitting operations across multiple EU jurisdictions. Kouloglou is the first confirmed PEGA Committee member to have been targeted with spyware during the period he was investigating spyware abuse, an irony that has driven 40+ civil society organizations -- including Access Now, Amnesty International, Privacy International, Reporters Without Borders, the Committee to Protect Journalists, and European Digital Rights -- to jointly demand an independent DG ITEC investigation, accelerated implementation of the PEGA Committee's own recommendations, and stronger enforcement of the EU Dual-Use Regulation against spyware vendors.
MITRE ATT&CK techniques used in TL-2026-2324
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Collection
T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages
Discovery
T1421 System Network Connections Discovery; T1426 System Information Discovery
Initial Access
T1456 Drive-By Compromise; T1664 Exploitation for Initial Access
command-and-control
Persistence
T1645 Compromise Client Software Binary
Execution
Affected products and versions in Pegasus Spyware Used to Hack Phone of Former MEP Stelios
- Apple — iOS
Vulnerable versions: iOS 15.x prior to 16.1 (MessagesBlastDoorService component); iOS 16.x prior to 16.3.1 (HomeKit component)
Fixed in: iOS 16.1 (BlastDoor mitigation); iOS 16.3.1 (HomeKit mitigation)
Remediation for Pegasus Spyware Used to Hack Phone of Former MEP Stelios
Patches
- Apple iOS 16.3.1 -- mitigated the HomeKit component of the PWNYOURHOME exploit chain.
- Apple iOS 16.1 -- mitigated the MessagesBlastDoorService component of the PWNYOURHOME exploit chain.
Immediate actions
- Run Mobile Verification Toolkit (MVT) or accept a Citizen Lab-style forensic exam on devices belonging to parliamentarians, journalists, and civil society figures showing an Apple threat notification.
- Enable Apple Lockdown Mode on devices of high-risk individuals -- Citizen Lab confirmed Lockdown Mode blocks PWNYOURHOME and surfaces a notification of the attempted attack.
- Treat any Apple threat notification as credible and route it to an independent forensic responder rather than the target's home government.
Workarounds
- Apple Lockdown Mode, available since iOS 16, blocks most zero-click messaging/HomeKit exploit surfaces used by PWNYOURHOME.
Longer-term hardening
- DG ITEC (European Parliament IT/security service) to conduct a full independent investigation into the hacking and assess whether other parliamentarians in oversight roles have been targeted.
- European Commission to respond to the PEGA Committee's 2023 recommendations with a concrete implementation status and roadmap.
- EU Member States to guarantee victims effective remedies: access to forensic evidence, independent investigation, and accountability mechanisms.
- Strengthen enforcement of the EU Dual-Use Regulation against spyware vendors and require fundamental-rights impact assessments before export licensing.
- Bar EU funds from supporting companies that develop or deploy commercial spyware absent binding human-rights safeguards.
Weaknesses (CWE) in Pegasus Spyware Used to Hack Phone of Former MEP Stelios
CWE-502
Timeline of Pegasus Spyware Used to Hack Phone of Former MEP Stelios
- Earliest known use of Pegasus against Russian civil society: exiled journalist Maria Epifanova (Novaya Gazeta Europe CEO) infected, later linked to the same attacker infrastructure used against Kouloglou.
- European Parliament establishes the PEGA Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware in the EU.
- Greek investigative journalist Thanasis Koukakis, previously confirmed by Citizen Lab to have been targeted with Intellexa's Predator spyware, testifies before the PEGA Committee.
- First confirmed Pegasus infection of Stelios Kouloglou's iPhone via the PWNYOURHOME zero-click exploit chain, at 10:16 UTC, while he was hospitalized in Greece and visited by Thanasis Koukakis.
- Israeli-Russian journalist Evgeny Erlikh infected with Pegasus in the linked Russian/Belarusian exile-targeting campaign documented in Access Now's 2024 report.
- Citizen Lab shares additional forensic artifacts on the PWNYOURHOME HomeKit component with Apple.
- Apple sends Kouloglou a state-sponsored threat notification.
- Second Pegasus infection period begins on Kouloglou's iPhone while he is in Brussels, running through March 7, 2023.
- Citizen Lab publicly discloses the PWNYOURHOME exploit chain (alongside sibling chains FINDMYPWN and LATENTIMAGE) in its 'Triple Threat' report.
- Apple sends Kouloglou a second threat notification.
- Apple sends Kouloglou a third threat notification.
- Access Now and Citizen Lab publish 'Civil Society in Exile: Pegasus,' documenting at least seven Russian- and Belarusian-speaking exiled journalists and activists targeted with Pegasus using infrastructure that overlaps with the Apple ID later confirmed in Kouloglou's case.
- Citizen Lab publishes 'Espionage Against the European Parliament,' confirming Kouloglou's two Pegasus infections and the shared attacker Apple ID linking his case to the 2024 Russian/Belarusian exile campaign.
- Access Now, joined by 40+ civil society organizations including Amnesty International and Reporters Without Borders, publishes a press release and joint statement demanding an independent DG ITEC investigation.
Sources cited for Pegasus Spyware Used to Hack Phone of Former MEP Stelios
- Same government, more victims: Access Now calls for an urgent investigation into hacking of MEP
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus
- By Whose Authority? Pegasus Targeting of Russian & Belarusian-Speaking Opposition Media Figures in Europe
- Exiled, then spied on: Civil society in Latvia, Lithuania, and Poland targeted with Pegasus spyware
- Joint Statement: Pegasus in the Parliament, the EU Must Act Now
- Politician who investigated spyware abuses had his phone hacked with Pegasus spyware
- Triple Threat: NSO Group's Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains
- Someone infected a spyware probe overseer with spyware
- European Parliament Member Investigating Spyware Was Hacked With Pegasus
- EU urged to act after Pegasus infects phone of spyware inquiry MEP
- NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab
- Pegasus spyware targeted exiled journalists from Russia, Latvia, Belarus
- Europe: Brazen hacking of former MEP investigating Pegasus abuses exposes painful inaction over spyware
- EU: Russian, Belarusian, Latvian, and Israeli journalists and activists in exile targeted by Pegasus spyware
More in malware
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique
Detection coverage for TL-2026-2324
As of 2026-09-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2324 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.