# Pegasus Spyware Targeted EU Parliamentarian Investigating Its Own Abuse
A chilling irony has emerged from the digital forensics laboratory at the Citizen Lab: the former European Parliament member tasked with investigating Pegasus spyware was himself repeatedly compromised with the same tool while serving on the parliamentary committee designed to curb its abuse. The discovery exposes a glaring vulnerability in democratic oversight — and raises uncomfortable questions about which governments possess authorization to deploy one of the world's most invasive surveillance platforms across multiple European nations.
## The Threat
Stelios Kouloglou, a former Member of the European Parliament from Greece, had his iPhone repeatedly compromised with NSO Group's Pegasus spyware while serving on the EU's "Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware" (PEGA Committee) from March 2022 through July 2023.
According to forensic analysis published by the Citizen Lab, Kouloglou's device was infected on at least two separate occasions:
Additionally, Kouloglou received three separate Apple threat notifications warning him of mercenary spyware targeting attempts:
"Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations," the Citizen Lab research team — including John Scott-Railton, Bill Marczak, and others — stated in their technical report.
## Background and Context
### The PEGA Committee's Mission
Established on March 10, 2022, the PEGA Committee represented an unprecedented effort by European lawmakers to systematically investigate the misuse of commercial spyware tools operating within the EU. The committee was tasked with examining:
Kouloglou served as an active member during the committee's most intensive period of investigation and evidence-gathering — making his compromise a direct assault on the institutional credibility of EU oversight mechanisms.
### Pegasus: The Weapon
NSO Group's Pegasus represents the most invasive commercially available mobile surveillance platform. Once installed, Pegasus grants operators complete access to:
The tool operates through zero-click exploits — meaning victims need not click a link or open a file. The attacker simply sends a specially crafted message, and the device is compromised silently.
## Technical Details
### The Attack Vector: PWNYOURHOME
The Citizen Lab identified that Kouloglou's iPhone was compromised through a zero-click vulnerability in Apple's HomeKit smart home framework, designated PWNYOURHOME. The attack sequence was methodical and sophisticated:
Initial Compromise (October 21, 2022):
rauharepo888[@]gmail.comThe HomeKit Exploit Chain:
| Component | Details |
|-----------|---------|
| Vulnerability | Zero-click RCE in HomeKit framework |
| CVE Status | Addressed in iOS 16.3.1 (February 2023) |
| Delivery Method | Crafted HomeKit message |
| User Interaction | None required |
| Persistence | Full device compromise |
The March 2023 infections similarly weaponized the same HomeKit vulnerability despite Kouloglou not updating to the patched iOS version.
### Infrastructure Links to Broader Campaigns
The Citizen Lab identified a critical overlap between Kouloglou's compromise and previous Pegasus campaigns targeting Russian and Belarusian-speaking exiled journalists and opposition activists across Europe. The connection: the same email address (rauharepo888[@]gmail.com) appeared in both attack chains.
"In our understanding of Pegasus infection infrastructure during this period, we believe that these emails are unique to specific operators," the Citizen Lab noted. This suggests a single Pegasus customer with authorization to operate across multiple European countries orchestrated both campaigns.
### Timing and Context
The targeting was remarkably well-coordinated with sensitive parliamentary activities:
## Implications
### Sovereignty and Accountability
The absence of attribution is as damning as confirmed attribution would be. The Citizen Lab explicitly states that no evidence implicates the Greek government. However, the infrastructure overlap with journalist/activist targeting campaigns indicates a Pegasus customer with multi-country authorization.
This raises a troubling question: Which EU member states possess NSO Group licenses? And are there safeguards preventing their misuse against other member states' lawmakers?
### Intelligence Gathering Against Democratic Institutions
If an operator accessed Kouloglou's device, they obtained:
The timing of attacks during critical drafting phases suggests the compromise was not passive monitoring but active intelligence gathering to influence the committee's recommendations.
### Regulatory Implications
The PEGA Committee ultimately recommended strict EU-level regulations limiting spyware deployment. Kouloglou's compromise demonstrates that even as lawmakers moved to restrict these tools, the operators deploying them faced no meaningful consequence.
## Recommendations
For EU Member States:
For Critical Figures and Institutions:
For Apple and Device Manufacturers:
## HackWire Analysis
The Pegasus targeting of EU Parliamentarian Stelios Kouloglou represents a watershed moment for the global surveillance accountability movement — and a profound indictment of current EU safeguards. For years, privacy advocates, journalists, and civil rights organizations have documented Pegasus abuse. The typical response: governments claim isolated misuse, oversight exists, and the tools serve legitimate security purposes.
But here's what makes Kouloglou's case different: a sitting member of an EU committee specifically tasked with investigating spyware abuse was himself targeted while performing his investigative duties. This wasn't collateral damage in a counterterrorism operation. This was a direct attack on democratic oversight itself.
The timing is damning. The March 2023 compromise occurred during the PEGA Committee's most critical phase — as lawmakers were drafting recommendations to restrict exactly this type of surveillance. An operator with multi-country Pegasus authorization clearly believed it was worth the risk to penetrate the committee's work. That calculation reveals something crucial: current enforcement mechanisms carry so little risk that targeting a European Parliament member seemed acceptable.
The unattributed status is perhaps most revealing. The Citizen Lab identified infrastructure overlap with journalist/activist campaigns, but stopped short of naming a nation-state. Yet we know Pegasus customers include only vetted governments. The deliberate ambiguity suggests either: (a) attribution is politically toxic for the EU to acknowledge, or (b) multiple EU allies are implicated. Either way, the silence itself speaks volumes.
For defenders, this case confirms what should be obvious: if you're investigating surveillance, you are a high-priority target for surveillance. Law enforcement, intelligence oversight bodies, and civil liberties organizations should assume they are already compromised or will be. The question isn't whether to harden defenses — it's whether current air-gapped, analog alternatives are the only truly secure approach to sensitive oversight work.
— HackWire Editorial
## Related Coverage