News Room
16
Share
Intellexa Sued for €8M in Athens as Pegasus Zero-Click Exploits Surface in EU Parliament Breach
criticalOffensive Tools

Intellexa Sued for €8M in Athens as Pegasus Zero-Click Exploits Surface in EU Parliament Breach

Victims of the 'Predatorgate' scandal have filed a landmark lawsuit in Greece against Intellexa, while Citizen Lab reveals NSO Group's Pegasus compromised EU investigators using sophisticated zero-click exploits.

08 July 2026Last updated 20 August 20265 min readCitizen Lab & Mandiant Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Europe
Confidence:
High Confidence
Source:
Citizen Lab & Mandiant Intelligence
Read Time:
5 min

Executive Summary\nOn July 7, 2026, eight victims of the long-running 'Predatorgate' wiretapping scandal filed a coordinated lawsuit in Athens against Intellexa SA and thirteen associated individuals, including founder Tal Dilian. Each plaintiff seeks €1 million in moral damages, totaling €8 million. This legal escalation coincides with a forensic report released by Citizen Lab, which confirmed that Stelios Kouloglou, a former Member of the European Parliament (MEP), was repeatedly targeted with NSO Group's Pegasus spyware while serving on the PEGA committee—the body investigating commercial surveillance abuse. These developments highlight a critical intersection between judicial pressure and the continued technical evolution of mercenary spyware reaching the highest levels of European governance.\n\n## Threat Analysis\nThe threat landscape in mid-2026 is characterized by the 'industrialization' of exploit development and a shift toward multi-platform surveillance. Commercial Surveillance Vendors (CSVs) have moved beyond simple data exfiltration to more intrusive, persistent, and occasionally destructive modules. For instance, the LightSpy framework (attributed to China-linked APT41) has evolved to version 7.9.0, now featuring 28 specialized plugins that can freeze devices or prevent booting—capabilities previously reserved for state-tier sabotage tools. In the European theater, the targeting of MEP Kouloglou suggests that surveillance operations are specifically timed to coincide with sensitive political deliberations, such as the drafting of EU-wide spyware regulations and parliamentary inquiries into the surveillance industry itself.\n\n## Technical Details\nThe compromise of MEP Kouloglou’s iPhone utilized the 'PWNYOURHOME' zero-click exploit, which weaponizes flaws in Apple’s HomeKit framework. Forensics identified a lookup for a specific HomeKit-linked email address (rauharepo888[@]gmail.com) followed immediately by Pegasus network activity. Unlike traditional phishing, this vector requires no user interaction and can persist across device updates if the underlying logic flaw is not mitigated via specific security configurations like Lockdown Mode. Simultaneously, exploit brokers like Crowdfense have reportedly increased bounties for such zero-click iOS chains to $7 million, reflecting the extreme difficulty of maintaining these capabilities in increasingly hardened mobile ecosystems that utilize memory tagging and improved sandbox isolation.\n\n## Attribution Assessment\nCitizen Lab’s analysis linked the Kouloglou infection to a Pegasus operator previously documented targeting Russian and Belarusian-speaking activists in May 2024. While the Greek government has denied involvement, the reuse of specific HomeKit identifiers suggests a single customer with cross-border authorization or a shared infrastructure model among NSO Group’s European government clients. For Intellexa’s Predator, the attribution remains tied to the network of firms in Ireland, North Macedonia, and Hungary sanctioned by the US Treasury in 2024. The lawsuit in Athens specifically names individuals like Tal Dilian, attempting to pierce the corporate veil that has historically shielded CSV executives from direct legal consequences.\n\n## Implications\nThe €8M lawsuit marks a shift toward personal liability for spyware executives. If successful, it establishes a precedent where victims can seek direct restitution from the technology providers, bypassing the sovereign immunity typically claimed by the purchasing nation-states. However, the discovery of ongoing Pegasus use within the EU Parliament demonstrates that existing sanctions and oversight committees (PEGA) have not yet deterred high-level surveillance. The emergence of 'destructive' modules in spyware like LightSpy also suggests that CSVs are broadening their service offerings from passive espionage to active operational disruption, significantly increasing the risk to critical human assets.\n\n## Recommendations\n1. Mobile Hardening: High-risk individuals, including journalists and public officials, must enable Apple's 'Lockdown Mode,' which significantly reduces the attack surface for HomeKit, iMessage, and Safari exploits.\n2. Device Hygiene: Daily reboots are recommended to clear non-persistent rootless jailbreaks commonly used by modern spyware to maintain a foothold in volatile memory.\n3. Telecom Security: Organizations should monitor for anomalous SS7/Diameter signaling traffic, as CSVs increasingly exploit telecom interconnects for location tracking and SMS interception.\n4. Forensic Audits: Public officials should undergo monthly device integrity checks via established forensic tools like the Mobile Verification Toolkit (MVT) to detect indicators of compromise (IOCs) such as unauthorized HomeKit lookups.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo