Surveillance Inception: When Mercenary Spyware Targets its own Watchdogs
New forensic evidence reveals that an EU spyware investigator was compromised by Pegasus during the probe. This marks a dangerous era where the watchdogs themselves are the primary targets.
The Infiltrated Inquiry
The report released this past Friday by Citizen Lab regarding former Greek MEP Stelios Kouloglou is a wake-up call that should reverberate through every high-level government office. It is not just that Kouloglou was hacked; it is that he was compromised by Pegasus while serving on the PEGA Committee—the very body tasked with investigating the illegal use of mercenary surveillance tools. This discovery proves that the wall between "legitimate investigation" and "active target" has been completely dismantled by private intelligence firms.
Why This Escalation Matters
For years, the cybersecurity community has framed mercenary spyware as a tool for suppressing dissent or state-on-state espionage. But targeting the investigators is a direct attack on democratic oversight. The timeline is damning: Kouloglou’s device was infected with NSO Group’s Pegasus in October 2022 and again in March 2023. These dates coincide perfectly with the committee’s most sensitive planning sessions and delegation visits to Greece and Cyprus.
This isn't just about data theft; it is about strategic paralysis. The infection utilized the 'PWNYOURHOME' zero-click exploit, which requires no user interaction and leaves minimal traces. If the very people investigating the surveillance industry cannot secure their own communications, the entire oversight framework is at risk of being manipulated or silenced by the entities they are supposed to be regulating.
The Legal Counter-Offensive
While the forensic news is grim, the legal landscape shifted significantly on July 7, 2026. Eight victims of the "Predatorgate" scandal filed a massive €8 million lawsuit in Athens against Intellexa SA and its founder, Tal Dilian. This represents a critical pivot in the war against mercenary spyware. We are moving from symbolic diplomatic sanctions and visa restrictions toward aggressive civil and criminal litigation. By targeting the personal wealth of founders and the corporate structures of the vendors, victims are forcing a financial cost on an industry that has long operated with impunity behind a veil of "government-only" sales.
Strategy for Leaders: Beyond the Zero-Day Obsession
Defenders and policy leaders must stop viewing mobile security as a solved problem through encryption.
- Adopt a "Compromised by Default" Model: For high-value targets and investigators, the mobile endpoint must be treated as hostile. Move sensitive deliberations off-device whenever possible.
- Aggressive Hardening: Lockdown Mode is no longer an optional feature for public figures; it is a baseline necessity.
- Financial Deterrence: Support legal frameworks that allow for the seizure of assets from exploit brokers and spyware vendors who fail to prevent human rights abuses.
The Outlook
The mercenary market is currently in a state of high-velocity mutation. As US and EU sanctions tighten on known entities like Intellexa, we are seeing the rise of more obscure exploit brokers—like the recently sanctioned 'Operation Zero'—who are specializing in the weaponization of the mobile patch gap. The battle for the mobile endpoint is no longer just a technical competition; it is a fundamental fight for the integrity of our democratic institutions.
