Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member

Pegasus Spyware Used to Hack Phone of Former MEP Stelios (TL-2026-2324), also tracked as PWNYOURHOME, is a high-severity malware campaign, first published 2026-09-04. It has no confirmed attribution, affects Apple iOS, maps to 14 MITRE ATT&CK techniques (T1404, T1409, T1421), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2324

Threat ID
TL-2026-2324
Also known as
PWNYOURHOME
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-04
Last reviewed
2026-09-04
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, news - media, civil society
Target regions
Europe, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
15

Malware and tooling in Pegasus Spyware Used to Hack Phone of Former MEP Stelios

Malware and tooling: Chrysaor, NSO Group Pegasus for iOS

Citizen Lab forensic analysis, published by Access Now on July 6, 2026, confirmed that the iPhone of Stelios Kouloglou -- a Greek journalist and former MEP who served on the European Parliament's PEGA Committee investigating spyware abuses -- was infected with NSO Group's Pegasus spyware on October 21, 2022 and again on March 6-7, 2023 via the zero-click PWNYOURHOME exploit chain. The attacker-controlled Apple ID used against Kouloglou (rauharepo888@gmail.com) was previously linked to the 2024 Access Now/Citizen Lab investigation into the hacking of exiled Russian and Belarusian journalists, though Citizen Lab found no evidence implicating the Greek, Russian, or Belarusian governments.

How Pegasus Spyware Used to Hack Phone of Former MEP Stelios works

On July 3, 2026, the Citizen Lab published forensic findings, amplified by an Access Now press release on July 6, 2026, showing that the iPhone of Stelios Kouloglou -- a Greek investigative journalist and former Member of the European Parliament who sat as a substitute member on Parliament's PEGA Committee of Inquiry into Pegasus and equivalent spyware -- was infected twice with NSO Group's Pegasus spyware. The first infection occurred on October 21, 2022 at 10:16 UTC while Kouloglou was hospitalized in Greece; that same day he was visited by fellow Greek journalist Thanasis Koukakis, who one month earlier had testified before the PEGA Committee about his own targeting with Intellexa's Predator spyware. A second infection window ran from March 6 to March 7, 2023 while Kouloglou was in Brussels for parliamentary business. Apple sent Kouloglou threat notifications on March 2, 2023, August 29, 2023, and April 10, 2024.

Both infections were delivered through PWNYOURHOME, a two-stage zero-click exploit chain that NSO Group began deploying against iOS 15 and 16 in October 2022. Citizen Lab's forensic analysis found a lookup for a HomeKit-associated email address, rauharepo888@gmail.com, immediately preceding the point at which a Pegasus process began using the device's mobile data connection -- consistent with the exploit's documented two-phase mechanism: a specially crafted NSKeyedArchive object is delivered to crash Apple's HomeKit daemon, and malicious content is then delivered to crash MessagesBlastDoorService, iMessage's sandboxed content-parsing service, achieving code execution without any interaction from the victim. Kouloglou's device was running iOS 15.5 (build 19F77) during both infection periods. Citizen Lab shared forensic artifacts on the HomeKit component with Apple in January 2023, and Apple shipped a fix in iOS 16.3.1; the MessagesBlastDoorService component had already been mitigated around iOS 16.1. Citizen Lab first disclosed PWNYOURHOME publicly, alongside two sibling zero-click chains (FINDMYPWN and LATENTIMAGE), in its April 18, 2023 'Triple Threat' report.

The forensic link that elevates this case beyond an isolated infection is infrastructure reuse: the same Apple ID, rauharepo888@gmail.com, appears as one of the redacted attacker identifiers in Access Now and Citizen Lab's May 30, 2024 report 'Civil Society in Exile: Pegasus,' which documented at least seven Russian- and Belarusian-speaking journalists and civil society members living in exile across Latvia, Lithuania, and Poland who were targeted with Pegasus between August 2020 and January 2023 -- including Novaya Gazeta Europe CEO Maria Epifanova (infected August 2020, the earliest known Pegasus use against Russian civil society), Israeli-Russian journalist Evgeny Erlikh (infected November 28-29, 2022), Latvian journalist Evgeniy Pavlov (targeted November 2022 and April 2023), and Belarusian opposition figure Andrei Sannikov. Citizen Lab explicitly states it has no evidence implicating the Greek, Russian, or Belarusian governments, but notes that because Kouloglou was infected in both Greece and Belgium, the responsible NSO Group customer likely held a license permitting operations across multiple EU jurisdictions. Kouloglou is the first confirmed PEGA Committee member to have been targeted with spyware during the period he was investigating spyware abuse, an irony that has driven 40+ civil society organizations -- including Access Now, Amnesty International, Privacy International, Reporters Without Borders, the Committee to Protect Journalists, and European Digital Rights -- to jointly demand an independent DG ITEC investigation, accelerated implementation of the PEGA Committee's own recommendations, and stronger enforcement of the EU Dual-Use Regulation against spyware vendors.

MITRE ATT&CK techniques used in TL-2026-2324

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Collection

T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages

Discovery

T1421 System Network Connections Discovery; T1426 System Information Discovery

Initial Access

T1456 Drive-By Compromise; T1664 Exploitation for Initial Access

command-and-control

T1644 Out of Band Data

Persistence

T1645 Compromise Client Software Binary

Execution

T1658 Exploitation for Client Execution

Affected products and versions in Pegasus Spyware Used to Hack Phone of Former MEP Stelios

  • Apple — iOS
    Vulnerable versions: iOS 15.x prior to 16.1 (MessagesBlastDoorService component); iOS 16.x prior to 16.3.1 (HomeKit component)
    Fixed in: iOS 16.1 (BlastDoor mitigation); iOS 16.3.1 (HomeKit mitigation)

Remediation for Pegasus Spyware Used to Hack Phone of Former MEP Stelios

Patches

  • Apple iOS 16.3.1 -- mitigated the HomeKit component of the PWNYOURHOME exploit chain.
  • Apple iOS 16.1 -- mitigated the MessagesBlastDoorService component of the PWNYOURHOME exploit chain.

Immediate actions

  • Run Mobile Verification Toolkit (MVT) or accept a Citizen Lab-style forensic exam on devices belonging to parliamentarians, journalists, and civil society figures showing an Apple threat notification.
  • Enable Apple Lockdown Mode on devices of high-risk individuals -- Citizen Lab confirmed Lockdown Mode blocks PWNYOURHOME and surfaces a notification of the attempted attack.
  • Treat any Apple threat notification as credible and route it to an independent forensic responder rather than the target's home government.

Workarounds

  • Apple Lockdown Mode, available since iOS 16, blocks most zero-click messaging/HomeKit exploit surfaces used by PWNYOURHOME.

Longer-term hardening

  • DG ITEC (European Parliament IT/security service) to conduct a full independent investigation into the hacking and assess whether other parliamentarians in oversight roles have been targeted.
  • European Commission to respond to the PEGA Committee's 2023 recommendations with a concrete implementation status and roadmap.
  • EU Member States to guarantee victims effective remedies: access to forensic evidence, independent investigation, and accountability mechanisms.
  • Strengthen enforcement of the EU Dual-Use Regulation against spyware vendors and require fundamental-rights impact assessments before export licensing.
  • Bar EU funds from supporting companies that develop or deploy commercial spyware absent binding human-rights safeguards.

Weaknesses (CWE) in Pegasus Spyware Used to Hack Phone of Former MEP Stelios

CWE-502

Timeline of Pegasus Spyware Used to Hack Phone of Former MEP Stelios

  • Earliest known use of Pegasus against Russian civil society: exiled journalist Maria Epifanova (Novaya Gazeta Europe CEO) infected, later linked to the same attacker infrastructure used against Kouloglou.
  • European Parliament establishes the PEGA Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware in the EU.
  • Greek investigative journalist Thanasis Koukakis, previously confirmed by Citizen Lab to have been targeted with Intellexa's Predator spyware, testifies before the PEGA Committee.
  • First confirmed Pegasus infection of Stelios Kouloglou's iPhone via the PWNYOURHOME zero-click exploit chain, at 10:16 UTC, while he was hospitalized in Greece and visited by Thanasis Koukakis.
  • Israeli-Russian journalist Evgeny Erlikh infected with Pegasus in the linked Russian/Belarusian exile-targeting campaign documented in Access Now's 2024 report.
  • Citizen Lab shares additional forensic artifacts on the PWNYOURHOME HomeKit component with Apple.
  • Apple sends Kouloglou a state-sponsored threat notification.
  • Second Pegasus infection period begins on Kouloglou's iPhone while he is in Brussels, running through March 7, 2023.
  • Citizen Lab publicly discloses the PWNYOURHOME exploit chain (alongside sibling chains FINDMYPWN and LATENTIMAGE) in its 'Triple Threat' report.
  • Apple sends Kouloglou a second threat notification.
  • Apple sends Kouloglou a third threat notification.
  • Access Now and Citizen Lab publish 'Civil Society in Exile: Pegasus,' documenting at least seven Russian- and Belarusian-speaking exiled journalists and activists targeted with Pegasus using infrastructure that overlaps with the Apple ID later confirmed in Kouloglou's case.
  • Citizen Lab publishes 'Espionage Against the European Parliament,' confirming Kouloglou's two Pegasus infections and the shared attacker Apple ID linking his case to the 2024 Russian/Belarusian exile campaign.
  • Access Now, joined by 40+ civil society organizations including Amnesty International and Reporters Without Borders, publishes a press release and joint statement demanding an independent DG ITEC investigation.

Sources cited for Pegasus Spyware Used to Hack Phone of Former MEP Stelios

More in malware

Detection coverage for TL-2026-2324

As of 2026-09-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2324 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats