{"id":1589,"date":"2026-07-03T11:51:56","date_gmt":"2026-07-03T11:51:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1589"},"modified":"2026-07-03T11:51:56","modified_gmt":"2026-07-03T11:51:56","slug":"european-parliament-member-investigating-spyware-was-hacked-with-pegasus","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1589","title":{"rendered":"European Parliament Member Investigating Spyware Was Hacked With Pegasus"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhC5WPtje84KYSxAYIbS54mCBmT7srsKokiZPsDcIbhcky59AAsHQYbWo4TrLsj3y1d7uI10DVgOt_5aEFaPQxKiwAPsJQJllaBBtuogSb7D8JF54_ahgzDstn8ST7WTRUAnhC10prFKCJgfkqEOW7m0o1yWDb-jzZFUWkzXEi65Sl5lyuLKr_4Da5ZpAgY\/s1700-e365\/iphone-spyware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial surveillance tools in the bloc.<\/p>\n<p>\u00abThrough forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations,\u00bb the Citizen Lab researchers John Scott-Railton, Bill Marczak, Bahr Abdul Razzak, Kate Pundyk, Siena Anstis, and Ron Deibert <a href=\"https:\/\/citizenlab.ca\/research\/member-of-committee-investigating-spyware-hacked-with-pegasus\/\">said<\/a>.<\/p>\n<p>The infections have not been attributed to a particular government at this time, and there is no evidence that the Greek government is behind the activity. However, the Canadian interdisciplinary research laboratory noted that it identified an overlap between the first infection and a previous campaign targeting Russian and Belarusian-speaking exiled journalists and activists in Europe.<\/p>\n<p>This indicates that a Pegasus customer with authorization to spy in multiple European countries is likely responsible for the effort, the Citizen Lab added.<\/p>\n<p>Kouloglou was a <a href=\"https:\/\/www.europarl.europa.eu\/meps\/en\/130833\/STELIOS_KOULOGLOU\/history\/9\">member<\/a> of the European Parliament&#8217;s \u00abCommittee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware\u00bb from March 24, 2022, to July 18, 2023. The PEGA Committee was <a href=\"https:\/\/www.europarl.europa.eu\/committees\/en\/archives\/9\/pega\/home\/welcome-words\">set up<\/a> on March 10, 2022, to probe alleged misuses of commercial spyware offerings under E.U. law, specifically focusing on gathering information on the extent to which member states and other countries are using such tools in contravention of the region&#8217;s rights and freedoms.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The Citizen Lab said that a forensic analysis of artifacts collected from his iPhone in May 2026 has found that it was compromised with Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023.<\/p>\n<p>\u00abOn 2022-10-21 10:16, there was a lookup for a HomeKit email address rauharepo888[@]gmail.com. Two minutes later, a Pegasus process used mobile data,\u00bb the researchers explained. It&#8217;s assessed that a zero-click exploit in Apple&#8217;s smart home software, codenamed <a href=\"https:\/\/thehackernews.com\/2023\/04\/nso-group-used-3-zero-click-iphone.html\">PWNYOURHOME, was used to deliver the spyware. The issue was addressed by Apple in iOS 16.3.1.<\/p>\n<p>The subsequent Pegasus activity observed in March 2023 is also said to have weaponized the same exploit. At both times, Kouloglou&#8217;s device was running iOS 15.5. Further analysis of the phone has revealed that Kouloglou received Apple threat notifications about being targeted with mercenary spyware on three occasions: March 2, 2023, August 29, 2023, and April 10, 2024.<\/p>\n<p>Interestingly, during the first time Kouloglou&#8217;s phone was hacked, he was admitted to a hospital for elective surgery and had been visited by Greek investigative journalist Thanasis Koukakis, who had his own phone compromised with Intellexa&#8217;s Predator spyware and had <a href=\"https:\/\/www.europarl.europa.eu\/committees\/en\/pega-hearing-on-use-of-spyware-in-greece\/product-details\/20220912CHE10601\">testified<\/a> before the PEGA Committee a month before.<\/p>\n<p>The timing of the second infection in March 2023 is also significant, as it coincided with the intense discussions related to the final drafting process, followed by a <a href=\"https:\/\/www.europarl.europa.eu\/committees\/en\/pega-exchange-of-views-on-a-european-sec\/product-details\/20230317CHE11454\">series of PEGA hearings<\/a>. The incident took place two months before the adoption of the <a href=\"https:\/\/www.europarl.europa.eu\/RegData\/etudes\/ATAG\/2023\/747923\/EPRS_ATA(2023)747923_EN.pdf\">first PEGA Committee report<\/a>.<\/p>\n<p>The development marks the first time a member of the PEGA Committee has been publicly identified as a victim of Pegasus spyware while serving on the committee.<\/p>\n<p>The connection between Kouloglou&#8217;s case and the campaign targeting Russian and Belarusian-speaking independent journalists and opposition activists based in Europe is based on the use of the same email address \u00abrauharepo888[@]gmail.com.\u00bb<\/p>\n<p>\u00abIn our understanding of Pegasus infection infrastructure during this period, we believe that these emails are unique to specific operators,\u00bb the Citizen Lab said. \u00abWe are unable to say whether the second infection in 2023 is similarly connected to this operator, or a different operator.\u00bb<\/p>\n<p>\u00abBased on what we know of NSO Group&#8217;s licensing, this would likely indicate that the customer had a license that enabled infections in multiple E.U. jurisdictions, narrowing the list of potential Pegasus operators that could be responsible for this case.\u00bb<\/p>\n<p>The findings raise fresh concerns about how governments leverage spyware ostensibly marketed for combating serious crimes, such as terrorism and child sexual abuse, for spying on the communications of journalists, lawmakers, dissidents, and critics.<\/p>\n<p>The development comes days after the Citizen Lab revealed that Russian authorities used Cellebrite&#8217;s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite announced it would stop offering its tools and services to Russia and Belarus.<\/p>\n<p>\u00abThe authorities searched Pivovarov&#8217;s devices for key organizations and contacts, as well as high-profile opposition figures,\u00bb the Citizen Lab said. \u00abSearch terms included Mikhail Khodorkovsky, who founded Open Russia, Anastasiya Burakova, who was at the time a human rights lawyer at Open Russia and currently leads a prominent anti-war group, and Open Russia&#8217;s former coordinator and Pivovarov&#8217;s partner, Tatiana Usmanova.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Some of these individuals, including Burakova, were later targeted in a phishing campaign orchestrated by a Russian hacking group known as COLDRIVER, raising the possibility that the use of Cellebrite&#8217;s tools may have helped facilitate reconnaissance and enable further targeting and surveillance of other regime opponents abroad.<\/p>\n<p>Back in April, the Citizen Lab also <a href=\"https:\/\/citizenlab.ca\/research\/uncovering-global-telecom-exploitation-by-covert-surveillance-actors\/\">uncovered<\/a> two distinct, long-running spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people&#8217;s locations. Notably, these attacks do not necessitate malware deployment, making them stealthy and harder to detect.<\/p>\n<p>One of two campaigns worked by sending a special type of text message with malicious hidden SMS commands to targets in an effort to \u00abturn the device into a covert tracking beacon,\u00bb the report said. The second campaign relied on <a href=\"https:\/\/en.wikipedia.org\/wiki\/Signalling_System_No._7#Protocol_security_vulnerabilities\">weaknesses<\/a> in Signaling System No. 7 (SS7) and Diameter signaling protocols to track an individual&#8217;s whereabouts without requiring access to their devices.<\/p>\n<p>The two campaigns are said to have abused three specific telecom providers, namely 019Mobile, Airtel Jersey (part of Sure Group), and Tango Networks U.K., that act as \u00absurveillance entry and transit points within the telecommunications ecosystem\u00bb and \u00aballow traffic to move through trusted signalling interconnections while granting access to threat actors that hide behind their infrastructure.\u00bb<\/p>\n<p>\u00abBoth actors used customized surveillance tooling to spoof operator identities, manipulate signalling protocols, and steer traffic through specific interconnect network paths to evade defenses and mask attribution,\u00bb the digital rights organization said.<\/p>\n<p>\u00abThe findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1590,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[79,715,663,2323,2322,2324,1030],"class_list":["post-1589","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-european","tag-hacked","tag-investigating","tag-member","tag-parliament","tag-pegasus","tag-spyware"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1589"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1589\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1590"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}