Pegasus Spyware Targets MEP Investigating Spyware Abuses
A member of the European Parliament's PEGA Committee — the body specifically tasked with investigating spyware abuse — had his personal phone compromised twice with NSO Group's Pegasus spyware during active proceedings. This attack highlights a chilling pattern of adversaries targeting the very individuals responsible for oversight and accountability, undermining democratic processes at their most critical moments. The sophistication of Pegasus, which can exploit zero-click vulnerabilities requiring no user interaction, makes traditional security awareness training insufficient on its own. This case underscores that high-value targets, especially those in politically sensitive roles, require proactive, device-level protections and dedicated threat intelligence support — not just policy guidance.
Tactical Insight
Immediate actions
- Deploy mobile threat defense (MTD) solutions on all devices used by high-risk individuals such as legislators, investigators, and journalists.
- Perform immediate forensic audits of devices belonging to personnel involved in sensitive investigations using tools like Amnesty International's Mobile Verification Toolkit (MVT).
- Issue dedicated, hardened devices (e.g., GrapheneOS-based phones) for official communications to individuals in high-profile oversight roles.
Long-term improvements
- Establish a formal threat model for staff in politically sensitive roles and mandate periodic device security reviews.
- Implement a zero-trust mobile device policy that restricts installation of third-party apps and enforces encrypted communications via vetted platforms.
- Engage with national CERTs or specialized groups like Citizen Lab to provide continuous threat intelligence relevant to targeted spyware campaigns.
Detection measures
- Schedule regular Pegasus/spyware scans using MVT or equivalent forensic tooling as part of a routine security hygiene programme.
- Enable centralised logging and anomaly detection for device telemetry to identify indicators of compromise (IOCs) associated with known spyware families.
- Create a clear, accessible incident reporting channel so staff can immediately escalate suspected device compromises to a dedicated security team.