Executive Summary
In October 2022 and March 2023, former Member of the European Parliament (MEP) Stelios Kouloglou's mobile device was infiltrated with Pegasus spyware while he was serving on the PEGA committee, which was investigating the misuse of such surveillance tools within the European Union. The Citizen Lab's forensic analysis confirmed these infections, indicating that attackers potentially accessed confidential committee documents and deliberations. The specific government or entity responsible for these attacks remains unidentified. (citizenlab.ca)
This incident underscores the escalating threat of sophisticated spyware targeting high-profile individuals, including those involved in oversight and investigative roles. It highlights the urgent need for robust cybersecurity measures and regulatory frameworks to protect sensitive information and uphold democratic processes. (theguardian.com)
Why This Matters Now
The targeting of a European Parliament member with Pegasus spyware while investigating its misuse highlights the pressing need for stringent regulations and enhanced cybersecurity measures to protect democratic institutions from sophisticated surveillance threats. (theguardian.com)
Attack Path Analysis
The attack began with the exploitation of a zero-click vulnerability in Apple's HomeKit, allowing Pegasus spyware to be installed on the target's device without any user interaction. Once installed, Pegasus gained root access, enabling it to escalate privileges and control the device fully. The spyware then moved laterally within the device, accessing various applications and data stores. It established a command and control channel to exfiltrate sensitive information, including confidential documents and communications. The exfiltrated data was transmitted to the attacker's servers, compromising the target's privacy and security. The impact included unauthorized access to sensitive information and potential surveillance of the target's activities.
Kill Chain Progression
Initial Compromise
Description
Exploitation of a zero-click vulnerability in Apple's HomeKit allowed Pegasus spyware to be installed without user interaction.
Related CVEs
CVE-2022-42827
CVSS 7.8An out-of-bounds write issue in the kernel allows a remote attacker to execute arbitrary code on affected devices.
Affected Products:
Apple iOS – < 16.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Drive-By Compromise
Exploitation for Initial Access
Exploitation for Privilege Escalation
Compromise Client Software Binary
Audio Capture
Location Tracking
Out of Band Data
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
CISA Zero Trust Maturity Model 2.0 – Identity Management
Control ID: Identity Pillar
ISO/IEC 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
DORA – ICT Risk Management Framework
Control ID: Article 5
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
European Parliament targeting demonstrates government officials face direct Pegasus spyware threats, requiring enhanced mobile security and encrypted communications infrastructure.
Law Enforcement
Commercial spyware abuse investigation reveals law enforcement vulnerabilities to state-sponsored surveillance, necessitating secure communication protocols and threat detection capabilities.
Computer/Network Security
Pegasus deployment against cybersecurity investigators exposes critical need for advanced mobile forensics, zero-trust architectures, and anti-surveillance security solutions.
Telecommunications
Mobile device compromise highlights telecommunications infrastructure vulnerabilities to commercial spyware, demanding encrypted traffic protection and anomaly detection systems.
Sources
- European Parliament Member Investigating Spyware Was Hacked With Pegasushttps://thehackernews.com/2026/07/european-parliament-member.htmlVerified
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasushttps://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/Verified
- Politician who investigated spyware abuses had his phone hacked with Pegasus spywarehttps://techcrunch.com/2026/07/02/politician-who-investigated-spyware-abuses-had-his-phone-hacked-with-pegasus-spyware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise may still occur, CNSF would likely limit the spyware's ability to communicate with other workloads, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Even with escalated privileges, the spyware would likely face restrictions in accessing other workloads, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The spyware's ability to move laterally would likely be constrained, reducing its capacity to access additional applications and data stores.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels would likely be detected and restricted, limiting the spyware's ability to communicate externally.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be identified and blocked, reducing the risk of sensitive information being transmitted to external servers.
While some unauthorized access may occur, the overall impact would likely be reduced due to constrained lateral movement and data exfiltration capabilities.
Impact at a Glance
Affected Business Functions
- Legislative Processes
- Confidential Communications
- Committee Deliberations
Estimated downtime: N/A
Estimated loss: N/A
Confidential committee documents and communications related to the investigation of spyware abuses.
Recommended Actions
Key Takeaways & Next Steps
- • Implement regular software updates to patch known vulnerabilities promptly.
- • Utilize intrusion prevention systems to detect and block exploit attempts.
- • Enforce strict application controls to limit unauthorized access.
- • Monitor network traffic for unusual patterns indicative of command and control communications.
- • Educate users on the risks of zero-click exploits and the importance of device security.



