CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Pegasus infection of PEGA-Committee MEP Stelios Kouloglou

incident · incident:pegasus-mep-kouloglou-pega-committee-2026

Citizen Lab forensic confirmation (2026-07-03) that former MEP Stelios Kouloglou's iPhone was infected twice with NSO Group's Pegasus spyware (Oct 2022 via PWNYOURHOME zero-click HomeKit→BlastDoor chain, and Mar 2023) while he served on the European Parliament's PEGA spyware-inquiry committee; unattributed but overlaps a Pegasus operator also targeting Russian/Belarusian-speaking exiles in Europe.

Aliases: Kouloglou Pegasus hack, PEGA Committee Pegasus targeting

Coverage
1
first 2026-07-03 → last 2026-07-03
Latest activity
2026-07-03
Citizen Lab confirms Pegasus infected a PEGA-Committee MEP via the PWNYOURHOME zero-click chain
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about Pegasus infection of PEGA-Committee MEP Stelios Kouloglou, newest first. Check the date before acting on an older one.

  • For officials in oversight, diplomatic, or inquiry roles handling sensitive material: enrol government-issued iPhones in Lockdown Mode (or an MDM-enforced equivalent that disables HomeKit and rich iMessage/attachment parsing) and Apple's at-risk threat-notification program.
    2026-07-03Citizen Lab confirms Pegasus infected a…
  • Establish proactive mobile forensic triage for high-risk principals, run the Mobile Verification Toolkit (MVT) against iOS sysdiagnose/backup artefacts periodically rather than waiting for an alert; a zero-click chain leaves no phishing artefact to hunt on the endpoint.
    2026-07-03Citizen Lab confirms Pegasus infected a…

Defender insights

What each entry about Pegasus infection of PEGA-Committee MEP Stelios Kouloglou tells a defender to do, newest first.

2026-07-03NOTABLECitizen Lab confirms Pegasus infected a PEGA-Committee MEP via the PWNYOURHOME zero-click chain

Story timeline

  1. 2026-07-03Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
    researchCitizen Lab confirms Pegasus infected a PEGA-Committee MEP via the PWNYOURHOME zero-click chain

Hunting pivots

Entries about Pegasus infection of PEGA-Committee MEP Stelios Kouloglou (1)

2026-07-03 · view entry permalink →

NOTABLE

Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus

Citizen Lab published a forensic report confirming, with high confidence, that the iPhone of Stelios Kouloglou (a former MEP who sat on the European Parliament's PEGA committee, the inquiry into commercial-spyware abuse) was infected with NSO Group's Pegasus on two occasions, around 21 October 2022 and 6–7 March 2023, while the device ran iOS 15.5 (Citizen Lab, 2026-07-03). The 2022 infection used the PWNYOURHOME zero-click chain: a specially crafted NSKeyedArchive object landing in the HomeKit daemon, followed by malicious content processed by MessagesBlastDoorService (iMessage's sandboxed attachment parser), a distinct path from earlier NSO chains that abused iMessage directly. Citizen Lab does not attribute the intrusion to any government and explicitly found no indication of Greek-government responsibility, but notes the targeting infrastructure overlaps a previously documented Pegasus campaign against Russian- and Belarusian-speaking exiled journalists and opposition figures in Europe, suggesting a single Pegasus customer with multi-country authorization (The Record, 2026-07-03). Because Kouloglou sat on the committee scrutinising exactly this abuse, the operator would have gained visibility into confidential PEGA deliberations, an EU parliamentary-privilege and confidentiality concern.

We found with high confidence that his device was successfully infected with Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023.

PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService.

Citizen Lab
research03 Jul 18:25Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • citizenlab.ca1 (50%)
  • therecord.media1 (50%)