# Pegasus Spyware Targeted EU Parliamentarian Investigating Its Own Abuse


A chilling irony has emerged from the digital forensics laboratory at the Citizen Lab: the former European Parliament member tasked with investigating Pegasus spyware was himself repeatedly compromised with the same tool while serving on the parliamentary committee designed to curb its abuse. The discovery exposes a glaring vulnerability in democratic oversight — and raises uncomfortable questions about which governments possess authorization to deploy one of the world's most invasive surveillance platforms across multiple European nations.


## The Threat


Stelios Kouloglou, a former Member of the European Parliament from Greece, had his iPhone repeatedly compromised with NSO Group's Pegasus spyware while serving on the EU's "Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware" (PEGA Committee) from March 2022 through July 2023.


According to forensic analysis published by the Citizen Lab, Kouloglou's device was infected on at least two separate occasions:


  • October 21, 2022 — During his hospitalization for elective surgery
  • March 6-7, 2023 — Coinciding with the committee's final report drafting and critical hearings

  • Additionally, Kouloglou received three separate Apple threat notifications warning him of mercenary spyware targeting attempts:

  • March 2, 2023
  • August 29, 2023
  • April 10, 2024

  • "Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations," the Citizen Lab research team — including John Scott-Railton, Bill Marczak, and others — stated in their technical report.


    ## Background and Context


    ### The PEGA Committee's Mission


    Established on March 10, 2022, the PEGA Committee represented an unprecedented effort by European lawmakers to systematically investigate the misuse of commercial spyware tools operating within the EU. The committee was tasked with examining:


  • The extent to which member states and other countries deployed surveillance tools
  • Violations of EU law regarding citizens' rights and freedoms
  • Recommendations for regulatory frameworks to prevent spyware abuse

  • Kouloglou served as an active member during the committee's most intensive period of investigation and evidence-gathering — making his compromise a direct assault on the institutional credibility of EU oversight mechanisms.


    ### Pegasus: The Weapon


    NSO Group's Pegasus represents the most invasive commercially available mobile surveillance platform. Once installed, Pegasus grants operators complete access to:


  • Call logs and message history
  • Location tracking
  • Calendar and contact data
  • Camera and microphone feeds
  • Encrypted messaging application content

  • The tool operates through zero-click exploits — meaning victims need not click a link or open a file. The attacker simply sends a specially crafted message, and the device is compromised silently.


    ## Technical Details


    ### The Attack Vector: PWNYOURHOME


    The Citizen Lab identified that Kouloglou's iPhone was compromised through a zero-click vulnerability in Apple's HomeKit smart home framework, designated PWNYOURHOME. The attack sequence was methodical and sophisticated:


    Initial Compromise (October 21, 2022):

  • A lookup occurred for the HomeKit email address rauharepo888[@]gmail.com
  • Exactly two minutes later, a Pegasus process initiated mobile data transmission
  • Kouloglou's device was running iOS 15.5 at the time
  • Apple did not patch this vulnerability until iOS 16.3.1

  • The HomeKit Exploit Chain:


    | Component | Details |

    |-----------|---------|

    | Vulnerability | Zero-click RCE in HomeKit framework |

    | CVE Status | Addressed in iOS 16.3.1 (February 2023) |

    | Delivery Method | Crafted HomeKit message |

    | User Interaction | None required |

    | Persistence | Full device compromise |


    The March 2023 infections similarly weaponized the same HomeKit vulnerability despite Kouloglou not updating to the patched iOS version.


    ### Infrastructure Links to Broader Campaigns


    The Citizen Lab identified a critical overlap between Kouloglou's compromise and previous Pegasus campaigns targeting Russian and Belarusian-speaking exiled journalists and opposition activists across Europe. The connection: the same email address (rauharepo888[@]gmail.com) appeared in both attack chains.


    "In our understanding of Pegasus infection infrastructure during this period, we believe that these emails are unique to specific operators," the Citizen Lab noted. This suggests a single Pegasus customer with authorization to operate across multiple European countries orchestrated both campaigns.


    ### Timing and Context


    The targeting was remarkably well-coordinated with sensitive parliamentary activities:


  • October 2022 infection: Occurred while Kouloglou was hospitalized, shortly after Greek investigative journalist Thanasis Koukakis testified before PEGA about his own compromise with Intellexa's Predator spyware
  • March 2023 infections: Aligned precisely with the committee's most intensive period — final report drafting and critical witness hearings
  • Pre-publication: The second compromise occurred two months before the PEGA Committee's initial report publication

  • ## Implications


    ### Sovereignty and Accountability


    The absence of attribution is as damning as confirmed attribution would be. The Citizen Lab explicitly states that no evidence implicates the Greek government. However, the infrastructure overlap with journalist/activist targeting campaigns indicates a Pegasus customer with multi-country authorization.


    This raises a troubling question: Which EU member states possess NSO Group licenses? And are there safeguards preventing their misuse against other member states' lawmakers?


    ### Intelligence Gathering Against Democratic Institutions


    If an operator accessed Kouloglou's device, they obtained:


  • Confidential committee deliberations and strategy documents
  • Testimony from witnesses before the inquiry
  • Legal analyses and regulatory recommendations
  • Communications with fellow committee members and EU leadership

  • The timing of attacks during critical drafting phases suggests the compromise was not passive monitoring but active intelligence gathering to influence the committee's recommendations.


    ### Regulatory Implications


    The PEGA Committee ultimately recommended strict EU-level regulations limiting spyware deployment. Kouloglou's compromise demonstrates that even as lawmakers moved to restrict these tools, the operators deploying them faced no meaningful consequence.


    ## Recommendations


    For EU Member States:

  • Conduct immediate audits of NSO Group licensing agreements and audit trails
  • Establish independent oversight of Pegasus deployment with real-time monitoring
  • Implement criminal penalties for unauthorized spyware use by state actors
  • Require transparency reports on any domestic Pegasus operations

  • For Critical Figures and Institutions:

  • Parliamentarians, judges, and law enforcement officials should assume advanced targeting threats
  • Implement device isolation protocols for handling classified material
  • Deploy zero-trust device security architectures
  • Consider hardware security keys and dedicated unconnected systems for sensitive communications

  • For Apple and Device Manufacturers:

  • Accelerate the patching cycle for zero-click exploits
  • Provide device-level telemetry that clearly surfaces infection attempts (not just notifications)
  • Consider forcing critical security updates for government and at-risk populations

  • ## HackWire Analysis


    The Pegasus targeting of EU Parliamentarian Stelios Kouloglou represents a watershed moment for the global surveillance accountability movement — and a profound indictment of current EU safeguards. For years, privacy advocates, journalists, and civil rights organizations have documented Pegasus abuse. The typical response: governments claim isolated misuse, oversight exists, and the tools serve legitimate security purposes.


    But here's what makes Kouloglou's case different: a sitting member of an EU committee specifically tasked with investigating spyware abuse was himself targeted while performing his investigative duties. This wasn't collateral damage in a counterterrorism operation. This was a direct attack on democratic oversight itself.


    The timing is damning. The March 2023 compromise occurred during the PEGA Committee's most critical phase — as lawmakers were drafting recommendations to restrict exactly this type of surveillance. An operator with multi-country Pegasus authorization clearly believed it was worth the risk to penetrate the committee's work. That calculation reveals something crucial: current enforcement mechanisms carry so little risk that targeting a European Parliament member seemed acceptable.


    The unattributed status is perhaps most revealing. The Citizen Lab identified infrastructure overlap with journalist/activist campaigns, but stopped short of naming a nation-state. Yet we know Pegasus customers include only vetted governments. The deliberate ambiguity suggests either: (a) attribution is politically toxic for the EU to acknowledge, or (b) multiple EU allies are implicated. Either way, the silence itself speaks volumes.


    For defenders, this case confirms what should be obvious: if you're investigating surveillance, you are a high-priority target for surveillance. Law enforcement, intelligence oversight bodies, and civil liberties organizations should assume they are already compromised or will be. The question isn't whether to harden defenses — it's whether current air-gapped, analog alternatives are the only truly secure approach to sensitive oversight work.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Spyware & Surveillance](https://www.hackwire.news/category/spyware) coverage
  • Cross-reference with [Government & Law Enforcement](https://www.hackwire.news/category/government) and [Mobile Security](https://www.hackwire.news/category/mobile-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)