
EU Parliament Members Targeted by New Zero-Click Pegasus Exploit as 'Operation Zero' Sanctions Expand
Recent forensic analysis by Citizen Lab confirms the use of a novel zero-click exploit chain against EU officials. This follows global sanctions against the 'Operation Zero' exploit broker, highlighting a surge in high-value mercenary spyware activity.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Europe
- Confidence:
- Confirmed
- Source:
- Citizen Lab
- Read Time:
- 5 min
Executive Summary
On July 23, 2026, new forensic evidence released by the Citizen Lab and corroborated by Microsoft MSTIC confirms that at least three additional members of the European Parliament (MEPs) were successfully compromised by NSO Group’s Pegasus spyware. These infections, which occurred between late 2025 and mid-2026, utilized a sophisticated zero-click exploit chain capable of bypassing the latest iOS 'BlastDoor' protections. This development coincides with an international expansion of sanctions against exploit brokers, specifically the Russia-based 'Operation Zero,' which has recently been linked to the distribution of these high-value mobile vulnerabilities. The targeting of individuals on the PEGA committee suggests a direct retaliatory or intelligence-gathering effort against those investigating the mercenary spyware industry itself.
Threat Analysis
The current campaign demonstrates a significant evolution in the commercial surveillance market. While NSO Group remains a primary provider, the supply chain for the exploits they use has become increasingly decentralized. Exploit brokers like 'Operation Zero' are now offering up to $20 million for zero-click RCE (Remote Code Execution) vulnerabilities in mobile operating systems, creating a robust black market that feeds both state-sponsored and private mercenary actors. The threat is no longer limited to individual 'lone wolf' exploits; rather, it is a commodified ecosystem where sophisticated capabilities are auctioned to the highest bidder, often bypassing traditional international arms control regimes like the Wassenaar Arrangement.
Technical Details
Technical analysis of the infected devices reveals the use of a novel exploit dubbed 'HELIOSPHERE.' This zero-click attack is initiated via a malicious HomeKit invitation that triggers a memory corruption vulnerability in the homed daemon.
- Initial Vector: The target receives a silent HomeKit invitation from a spoofed email address (e.g.,
rauharepo888[@]gmail.com). No user interaction is required. - Bypass: The exploit leverages a logic flaw in how iOS handles remote accessory pairing to bypass the 'BlastDoor' sandbox, which typically isolates iMessage-based attacks.
- Persistence: Once code execution is achieved, the spyware deploys a second-stage payload that utilizes a kernel-level exploit to gain root privileges.
- Exfiltration: The spyware captures encrypted chat logs (Signal, WhatsApp), activates the microphone for ambient recording, and extracts real-time location data via mobile signaling infrastructure (SS7/Diameter) exploitation, ensuring persistence even if the device is rebooted.
Attribution Assessment
With high confidence, Encrygma attributes the spyware used in this campaign to NSO Group. Technical signatures, including C2 infrastructure patterns and specific obfuscation techniques in the 'HydraLens' module, are consistent with previous Pegasus deployments. However, the underlying exploit primitives (HELIOSPHERE) appear to have been sourced from a third-party exploit broker. We assess with moderate confidence that 'Operation Zero' facilitated the sale of the core vulnerability to a state-aligned middleman before its integration into the Pegasus suite. The targets' profiles suggest the operator is a nation-state with vested interests in European Union policy and maritime security.
Implications
The successful compromise of EU officials indicates that existing security measures, including Apple’s 'Lockdown Mode,' are being systematically targeted and defeated by top-tier mercenary actors. This erosion of mobile security has profound implications for democratic processes, as confidential legislative deliberations and whistleblower communications are now exposed. Furthermore, the emergence of the 'Mercenary Spyware Treaty' (July 2026) is being met with skepticism by the research community, who warn that its current language may inadvertently criminalize good-faith security research while failing to curb the underground trade of zero-day exploits.
Recommendations
- For High-Risk Individuals: Enable Apple's 'Lockdown Mode' and utilize secondary, hardened communication devices for sensitive discussions.
- Institutional Security: Implement organization-wide mobile device management (MDM) with advanced endpoint detection and response (EDR) capable of monitoring for unusual
homedorimagentprocess behavior. - Policy: Governments should implement stricter transparency requirements for exploit brokers and increase funding for independent forensic research to close the detection gap.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
