google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
UK

Spyware used against MEP investigating Pegasus abuses, report finds | Espionage

NSO Group’s hacking software was used repeatedly against a member of the European parliament leading an investigation into spyware abuses in Europe, according to a new report.

Researchers at the University of Toronto Citizen Lab said they could not attribute the attacks against Stelios Kouloglou to any government operative using the Pegasus spyware. However, their investigation revealed that the attack on the former Greek MP bore traces of a previous hacking campaign against Russian and Belarusian journalists exiled in Europe.

“You become angry when you realize that your private life is being scrutinized by very bad people,” Kouloglou, who is also a journalist and left parliament in 2024, said in an interview. “This corruption is a big problem with justice and democracy.”

At the heart of Citizen Lab’s new report is Kouloglou’s work for a special European parliamentary committee known as Pega, which was set up following the publication of the Pegasus Project by the Guardian and a consortium of media organizations in March 2022.

Project Pegasus has revealed how journalists, activists, politicians and other members of civil society are being targeted by governments using Pegasus, which is produced by Israel-based NSO Group and sold to governments around the world to stop serious crimes and terrorist attacks. Pega’s mission in 2022 was to investigate the extent of how spyware is being used contrary to EU law.

Kouloglou, a journalist who was first elected to the European parliament as a member of the Syriza party, joined the Pega committee in March 2022. Nearly seven months later, on October 21, 2022, his mobile device was first infected, Citizen Lab said, during what it described as a “period of particularly intense activity” in Pega’s deliberations and investigations, including the drafting of the committee’s first report.

NSO did not respond to a request for comment.

The hacking incident coincided with Kouloglou being admitted to hospital for elective surgery, where he was visited by Greek investigative journalist Thanasis Koukakis.

At the time, Koukakis was working on paid spyware stories in Greece following a major scandal known as the “Greek Water Gate” that involved the illegal targeting of more than 80 people in Greece, including politicians, journalists and military officials. Koukakis was among the targeted victims and had previously testified before the Pega committee about his experience.

Citizen Lab said Kouloglou’s device was hacked again on March 6 and 7, 2023, when Pega was involved in intense discussions on the final draft of his report. The hacking incident coincided with Kouloglou’s trip from Athens to Brussels.

Citizen Lab said the disclosures in its reports marked the first time it was known that a member of the Pega committee was the target of spyware. This happened because the committee’s recommendations were essentially ignored, said John Scott-Railton, a senior researcher at Citizen Lab.

skip past newsletter introduction


He said: “This case is the great irony of Europe’s spyware crisis. A member of the committee tasked with investigating Pegasus was affected. So what has happened since then? When new spyware exploits emerge in Europe, parliament turns a blind eye.”

“I can tell you how the next chapter will play out: more parliamentarians being hacked. In fact, I suspect there are members voting and attending high-level meetings unaware that their phone has been turned into a spy in their pocket.”

While Citizen Lab was unable to locate the prospective government client who used the spyware against the then-member of the European Parliament, researchers said they believe the operator who targeted him also targeted seven Russian- and Belarusian-speaking independent journalists and opposition activists based in Europe who were found to have targeted or been infected with the Pegasus spyware.

Researchers identified a unique Apple ID email used in the attacks; This suggests that the attacks were carried out by the same government client. The customer likely also has a license to operate in Belgium and Greece, Citizen Lab said.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button