News Room
16
Share
EU Parliament Members Targeted by New Zero-Click Pegasus Exploit as 'Operation Zero' Sanctions Expand
criticalOffensive Tools

EU Parliament Members Targeted by New Zero-Click Pegasus Exploit as 'Operation Zero' Sanctions Expand

Recent forensic analysis by Citizen Lab confirms the use of a novel zero-click exploit chain against EU officials. This follows global sanctions against the 'Operation Zero' exploit broker, highlighting a surge in high-value mercenary spyware activity.

23 July 2026Last updated 20 August 20265 min readCitizen Lab
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Europe
Confidence:
Confirmed
Source:
Citizen Lab
Read Time:
5 min

Executive Summary

On July 23, 2026, new forensic evidence released by the Citizen Lab and corroborated by Microsoft MSTIC confirms that at least three additional members of the European Parliament (MEPs) were successfully compromised by NSO Group’s Pegasus spyware. These infections, which occurred between late 2025 and mid-2026, utilized a sophisticated zero-click exploit chain capable of bypassing the latest iOS 'BlastDoor' protections. This development coincides with an international expansion of sanctions against exploit brokers, specifically the Russia-based 'Operation Zero,' which has recently been linked to the distribution of these high-value mobile vulnerabilities. The targeting of individuals on the PEGA committee suggests a direct retaliatory or intelligence-gathering effort against those investigating the mercenary spyware industry itself.

Threat Analysis

The current campaign demonstrates a significant evolution in the commercial surveillance market. While NSO Group remains a primary provider, the supply chain for the exploits they use has become increasingly decentralized. Exploit brokers like 'Operation Zero' are now offering up to $20 million for zero-click RCE (Remote Code Execution) vulnerabilities in mobile operating systems, creating a robust black market that feeds both state-sponsored and private mercenary actors. The threat is no longer limited to individual 'lone wolf' exploits; rather, it is a commodified ecosystem where sophisticated capabilities are auctioned to the highest bidder, often bypassing traditional international arms control regimes like the Wassenaar Arrangement.

Technical Details

Technical analysis of the infected devices reveals the use of a novel exploit dubbed 'HELIOSPHERE.' This zero-click attack is initiated via a malicious HomeKit invitation that triggers a memory corruption vulnerability in the homed daemon.

  1. Initial Vector: The target receives a silent HomeKit invitation from a spoofed email address (e.g., rauharepo888[@]gmail.com). No user interaction is required.
  2. Bypass: The exploit leverages a logic flaw in how iOS handles remote accessory pairing to bypass the 'BlastDoor' sandbox, which typically isolates iMessage-based attacks.
  3. Persistence: Once code execution is achieved, the spyware deploys a second-stage payload that utilizes a kernel-level exploit to gain root privileges.
  4. Exfiltration: The spyware captures encrypted chat logs (Signal, WhatsApp), activates the microphone for ambient recording, and extracts real-time location data via mobile signaling infrastructure (SS7/Diameter) exploitation, ensuring persistence even if the device is rebooted.

Attribution Assessment

With high confidence, Encrygma attributes the spyware used in this campaign to NSO Group. Technical signatures, including C2 infrastructure patterns and specific obfuscation techniques in the 'HydraLens' module, are consistent with previous Pegasus deployments. However, the underlying exploit primitives (HELIOSPHERE) appear to have been sourced from a third-party exploit broker. We assess with moderate confidence that 'Operation Zero' facilitated the sale of the core vulnerability to a state-aligned middleman before its integration into the Pegasus suite. The targets' profiles suggest the operator is a nation-state with vested interests in European Union policy and maritime security.

Implications

The successful compromise of EU officials indicates that existing security measures, including Apple’s 'Lockdown Mode,' are being systematically targeted and defeated by top-tier mercenary actors. This erosion of mobile security has profound implications for democratic processes, as confidential legislative deliberations and whistleblower communications are now exposed. Furthermore, the emergence of the 'Mercenary Spyware Treaty' (July 2026) is being met with skepticism by the research community, who warn that its current language may inadvertently criminalize good-faith security research while failing to curb the underground trade of zero-day exploits.

Recommendations

  • For High-Risk Individuals: Enable Apple's 'Lockdown Mode' and utilize secondary, hardened communication devices for sensitive discussions.
  • Institutional Security: Implement organization-wide mobile device management (MDM) with advanced endpoint detection and response (EDR) capable of monitoring for unusual homed or imagent process behavior.
  • Policy: Governments should implement stricter transparency requirements for exploit brokers and increase funding for independent forensic research to close the detection gap.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo