ctipilot.ch

Pegasus infection of PEGA-Committee MEP Stelios Kouloglou

incident · incident:pegasus-mep-kouloglou-pega-committee-2026

Citizen Lab forensic confirmation (2026-07-03) that former MEP Stelios Kouloglou's iPhone was infected twice with NSO Group's Pegasus spyware (Oct 2022 via PWNYOURHOME zero-click HomeKit→BlastDoor chain, and Mar 2023) while he served on the European Parliament's PEGA spyware-inquiry committee; unattributed but overlaps a Pegasus operator also targeting Russian/Belarusian-speaking exiles in Europe.

Aliases: Kouloglou Pegasus hack, PEGA Committee Pegasus targeting

Coverage timeline
2
first 2026-07-03 → last 2026-07-05
Peak priority
high
1 high · 1 notable
Sources cited
4
4 hosts
Sections touched
2
research, weekly-sector-patterns
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
2026-07-032 appearances2026-07-05

Story timeline

  1. 2026-07-05Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach
    weekly-sector-patternsPublic-administration targeting this week — Canton Zürich leak claim, Pegasus-infected MEP, DHS HSIN breach
  2. 2026-07-03Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
    researchCitizen Lab confirms Pegasus infected a PEGA-Committee MEP via the PWNYOURHOME zero-click chain

Where this entity is cited

  • research1
  • weekly-sector-patterns1

Source distribution

  • bleepingcomputer.com1 (25%)
  • citizenlab.ca1 (25%)
  • ransomware.live1 (25%)
  • therecord.media1 (25%)

explore in graph

Entries about Pegasus infection of PEGA-Committee MEP Stelios Kouloglou (2)

2026-07-05 · view entry permalink →

HIGHNATOB2

Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach

Three unrelated events this week share one thing: the victim is a public institution, and each demonstrates a different way government is reached — extortion branding, mercenary spyware, and inter-agency trust boundaries. For a Swiss federal SOC the value is the pattern across the target class, not any single incident.

A Swiss cantonal department on a leak site (unconfirmed). MedusaLocker listed a victim "Bd" with domain bd.zh.ch — the Baudirektion of the Canton of Zürich — on 2026-07-01, claiming 772 extracted emails, as part of a batch-style posting wave that also listed a French municipality and other European entities in immediate succession (Ransomware.live, 2026-07-01). This is a dark-web claim only: no cantonal statement, no NCSC.ch (BACS) advisory, no independent Swiss press coverage exists in-window. It is a situational-awareness signal for cantonal-government readers, not a confirmed breach — but batch-listing of European public bodies is itself the operational note (§ references).

A Pegasus-infected European Parliament oversight member. Citizen Lab confirmed with high confidence that the iPhone of former MEP Stelios Kouloglou — who sat on the Parliament's PEGA committee investigating commercial-spyware abuse — was infected with NSO Group's Pegasus twice (Oct 2022 and Mar 2023) via the zero-click PWNYOURHOME chain (a crafted NSKeyedArchive landing in the HomeKit daemon, then malicious content in MessagesBlastDoorService) (Citizen Lab, 2026-07-03). The targeting infrastructure overlaps a Pegasus operator also hitting Russian/Belarusian-speaking exiles in Europe. Infecting the person scrutinising spyware abuse is an EU parliamentary-privilege concern, and the defensive surface for high-risk officials is proactive mobile forensics plus enforced Lockdown Mode — not endpoint alerting.

A US federal information-sharing platform. DHS confirmed a breach of the Homeland Security Information Network — the platform federal/state/local/international/private-sector partners use to exchange sensitive-but-unclassified information — with intrusion believed to be late-May–early-June and a SharePoint collaboration system implicated; DHS says no classified networks were impacted (BleepingComputer, 2026-07-01). Both this and HSIN's 2023 incident trace to collaboration-platform trust boundaries rather than perimeter exploitation.

Builds on: 2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek · 2026-07-03/citizen-lab-pega-committee-mep-infected-with-pegasus · 2026-07-02/dhs-confirms-a-breach-of-the-homeland-security-information-n

synthesis05 Jul 23:31Zmulti-sourceOpen finding ↗

2026-07-03 · view entry permalink →

NOTABLE

Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus

Citizen Lab published a forensic report confirming, with high confidence, that the iPhone of Stelios Kouloglou — a former MEP who sat on the European Parliament's PEGA committee, the inquiry into commercial-spyware abuse — was infected with NSO Group's Pegasus on two occasions, around 21 October 2022 and 6–7 March 2023, while the device ran iOS 15.5 (Citizen Lab, 2026-07-03). The 2022 infection used the PWNYOURHOME zero-click chain: a specially crafted NSKeyedArchive object landing in the HomeKit daemon, followed by malicious content processed by MessagesBlastDoorService (iMessage's sandboxed attachment parser) — a distinct path from earlier NSO chains that abused iMessage directly. Citizen Lab does not attribute the intrusion to any government and explicitly found no indication of Greek-government responsibility, but notes the targeting infrastructure overlaps a previously documented Pegasus campaign against Russian- and Belarusian-speaking exiled journalists and opposition figures in Europe, suggesting a single Pegasus customer with multi-country authorization (The Record, 2026-07-03). Because Kouloglou sat on the committee scrutinising exactly this abuse, the operator would have gained visibility into confidential PEGA deliberations — an EU parliamentary-privilege and confidentiality concern.

We found with high confidence that his device was successfully infected with Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023.

PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService.

Citizen Lab
research03 Jul 18:25Zmulti-sourceOpen finding ↗