메뉴
HN
Hacker News 25일 전

유럽의회 페가수스 감시 활동 사건

IMP
8/10
핵심 요약

페가수스(Pegasus) 스파이웨어 남용을 조사하던 유럽의회(PEGA) 위원회 소속 의원인 스텔리오스 쿨로그루(Stelios Kouloglou)의 휴대전화가 동일한 스파이웨어로 반복적으로 해킹당한 사실이 포렌식 분석을 통해 확인되었습니다. 특히 1차 해킹은 러시아 및 벨라루스 망명 언론인들을 겨냥한 이전 캠페인과 연관성이 높아, 다수의 유럽 국가를 감시할 수 있는 권한을 가진 특정 Pegasus 고객이 배후인 것으로 추정됩니다. 이는 국가급 해킹 도구가 위원회의 기밀 유출을 초래할 수 있음을 시연하는 중대한 정보보안 및 정치적 사건입니다.

번역된 본문

목차 주요 발견 사항 배경 쿨로그루, 페가수스 스파이웨어에 감염 표적 공격의 배경 및 PEGA 위원회 활동 감시받는 유럽의회 배후 추정 결론 부록: PEGA 심의 및 감염 일정

주요 발견 사항 유럽의회 전 의원인 스텔리오스 쿨로그루(Stelios Kouloglou)는 페가수스(Pegasus) 스파이웨어 남용을 조사하는 위원회에서 활동하는 동안 NSO 그룹의 페가수스 스파이웨어에 의해 반복적으로 해킹당했습니다. 쿨로그루는 PEGA 위원회 활동의 핵심적인 시기에 감염되었으며, 이 스파이웨어는 위원회 활동에 대한 비공개 정보를 빼냈을 가능성이 높습니다. 이는 EU 의회의 기밀 유지 및 특권 프레임워크를 위반했을 수 있습니다. 우리는 현재 이러한 감염을 특정 정부의 소행으로 귀인(Attribution)하고 있지 않으며, 그리스 정부가 책임이 있다는 징후는 발견되지 않았습니다. 대신, 우리는 첫 번째 감염과 유럽에 체류 중인 러시아 및 벨라루스어권 망명 언론인과 활동가를 표적으로 삼았던 이전에 식별된 페가수스 캠페인 사이의 교집합에 주목합니다. 이는 다수의 유럽 국가에서 감시 권한을 가진 페가수스 고객이 이 사건의 배후임을 시사합니다.

배경 스텔리오스 쿨로그루는 저명한 그리스 탐사 보도 언론인으로, 2015년에 유럽의회 의원으로 선출되었습니다. 그는 파리(1983-84), 모스크바(1989-93), 유고슬라비아(1992-95)에서 그리스 라디오 및 TV의 기자로 활동했습니다. 이후 2008년부터 '국경 없는 텔레비전(TVXS)'을 설립하고 기자로 일했습니다. 쿨로그루는 시리자(Syriza) 당의 선거 명부(좌파 계열)에 무소속으로 출마하여 유럽의회 의원으로 선출되었습니다. 그는 2019년 유럽 선거에서 다음 의회 임기의 의원으로 재선되었습니다. 쿨로그루는 2022년 3월 24일부터 2023년 7월 18일까지 페가수스 및 동급의 감시 스파이웨어 사용을 조사하기 위한 유럽의회 조사 위원회(PEGA 위원회)의 교체 위원으로 활동했습니다. PEGA 위원회는 2021년 '페가수스 프로젝트'의 발표 및 유럽 정부가 언론인, 활동가, 정치인 및 기타 시민들을 감시하기 위해 스파이웨어를 사용했다는 사실을 폭로한 다른 보도들에 따라 2022년 3월 10일에 설립되었습니다. 유럽의회 의원(MEP) 소피 인트 벨트(Sophie in 't Veld)가 이끄는 PEGA 위원회는 EU 법률을 위반하는 스파이웨어 사용 범위를 조사하는 임무를 맡았으며, 특히 '페가수스 및 동급의 감시 스파이웨어'에 중점을 두었습니다. 유럽의회 의원으로 재직하는 동안 쿨로그루는 계속해서 칼럼을 쓰고 TVXS를 통해 보도했습니다. 그는 2023년 10월 시리자 당을 탈당하고 2024년 6월 선거 때까지 무소속으로 활동했으며, 이후 '새로운 좌파(New Left)'의 일원으로 활동했습니다. 그의 의회 임기는 2024년 7월에 종료되었습니다.

쿨로그루, 페가수스 스파이웨어에 감염 2026년 5월(역주: 원문 기준), 쿨로그루가 시티즌 랩(Citizen Lab)에 연락해 왔으며, 우리는 그의 아이폰에서 수집된 아티팩트에 대한 포렌식 분석을 수행했습니다. 우리는 높은 신뢰도로 그의 기기가 2022년 10월 21일경, 그리고 2023년 3월 6일과 7일에 페가수스 스파이웨어에 성공적으로 감염되었음을 발견했습니다. 2022년 10월 21일 10시 16분에 HomeKit 이메일 주소인 rauharepo888 [@]gmail.com에 대한 조회가 발생했습니다. 2분 후, 페가수스 프로세스가 모바일 데이터를 사용했습니다. 우리는 이 시점에 해당 휴대전화가 PWNYOURHOME 제로 클릭(Zero-click) 익스플로잇을 통해 해킹되었다고 평가합니다. PWNYOURHOME은 공격자가 HomeKit에 전달되도록 특수하게 제작된 NSKeyedArchive를 먼저 보낸 다음, MessagesBlastDoorService에 악성 콘텐츠를 전달하는 방식으로 진행된 것으로 보입니다. 애플(Apple)은 iOS 16.3.1에서 HomeKit에 대한 변경을 통해 첫 번째 문제를 완화했지만, MessagesBlastDoorService 문제는 iOS 16.1에서 이미 수정한 것으로 평가됩니다. 또한 우리는 2023년 3월 6일 09시 49분부터 3월 7일 07시 30분 사이에 쿨로그루의 기기에서 페가수스 활동을 확인했으며, 이는 동일한 익스플로잇과 관련된 것으로 평가됩니다. 2022년과 2023년 감염 당시, 해당 기기는 iOS 15.5 (19F77) 버전이 실행 중이었습니다. 이러한 발견은 사용 가능한 포렌식 데이터의 한계로 인해 우리가 포착하지 못한 추가적인 감염 가능성을 배제하지 않습니다. 애플 알림: 포렌식 분석 결과 쿨로그루(이하 생략, 원문 단절)

원문 보기
원문 보기 (영어)
Contents Key Findings Background Kouloglou Infected with Pegasus Spyware Targeting Context and PEGA Committee Activities The European Parliament Under Surveillance Attribution Conclusion Appendix: Timeline of PEGA Deliberations and Infection Dates Key Findings Former Member of the European Parliament, Stelios Kouloglou , was repeatedly hacked with NSO Group’s Pegasus spyware while on the committee investigating Pegasus spyware abuses. Kouloglou was infected during key periods of PEGA committee activity, and the spyware would have likely captured non-public information about committee activities, possibly breaching EU parliamentary confidentiality and privilege frameworks. We are not attributing these infections to a particular government at this time, and found no indications that the Greek Government is responsible. Instead, we note an overlap between the first infection and a previously identified Pegasus campaign targeting Russian and Belarusian-speaking exiled journalists and activists in Europe, suggesting a Pegasus customer with authorization to spy in multiple European countries is responsible. Background Stelios Kouloglou is a prominent Greek investigative journalist who was elected as a Member of the European Parliament in 2015. He reported for Greek radio and TV from Paris (1983-84), Moscow (1989-93), and Yugoslavia (1992-95). He later founded and reported for Television Without Borders ( TVXS ) starting in 2008. Kouloglou was elected to the European parliament as an independent in the Syriza party ’s electoral list (affiliated with the Left). He was elected to the next parliamentary term in the 2019 European elections. Kouloglou was a substitute member of the European Parliament’s Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware ( PEGA Committee ) from March 24, 2022 to July 18, 2023. The PEGA Committee was established on March 10, 2022 following the 2021 publication of the Pegasus Project and other reporting which revealed European governments used spyware to surveil journalists, activists, politicians, and other citizens. Led by MEP Sophie in ‘t Veld, the PEGA Committee was tasked to investigate the scope of spyware usage in contravention of EU law, focusing on “Pegasus and equivalent surveillance spyware.” While sitting as an MEP, Kouloglou continued to write opinion pieces and report for TVXS. He left the Syriza party in October 2023 and sat as an independent until the elections of June 2024, after which he served as a member of the New Left. His parliamentary term ended in July 2024. Kouloglou Infected with Pegasus Spyware In May 2026, Kouloglou contacted the Citizen Lab and we conducted a forensic analysis of artifacts from his iPhone. We found with high confidence that his device was successfully infected with Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023. On 2022-10-21 10:16, there was a lookup for a HomeKit email address rauharepo888 [@]gmail.com . Two minutes later, a Pegasus process used mobile data. We assess that the phone was hacked with the PWNYOURHOME zero-click exploit at this point. PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService. Apple mitigated the first issue with a change to HomeKit in iOS 16.3.1, though we assess that they fixed the MessagesBlastDoorServiceissue earlier, likely in iOS 16.1. We additionally saw Pegasus activity on Kouloglou’s device between 2023-03-06 09:49 and 2023-03-07 07:30 that we assess is likely linked to the same exploit. On the 2022 and 2023 dates, we assess that the device was running iOS 15.5 (19F77). These findings do not preclude the possibility of additional infections that we have been unable to capture due to limitations of available forensic data. Apple Notifications Further validating our finding of targeting, our forensic analysis shows Kouloglou received multiple Apple threat notifications about targeting with mercenary spyware on three occasions: March 2, 2023, August 29, 2023, and April 10, 2024. It is important to note that threat notifications from Apple and other companies are not real-time alerts. They are typically sent to users in batches, often months or more after targeting takes place. Kouloglou reports to us that he did not recall receiving the Apple notifications we observed. Targeting Context and PEGA Committee Activities Kouloglou helped the Citizen Lab reconstruct his activities during the periods when he was targeted with Pegasus spyware (see the detailed timeline in the Appendix ). Throughout the period under consideration, Kouloglou wrote numerous articles and gave frequent interviews about spyware abuses. We summarize the key contextual details in the following sections. First Pegasus Infection Period: PEGA Hearing Prep, Country Visits The date of the first known Pegasus infection of Kouloglou’s device – October 21, 2022 – aligns with a particularly intense period of activity around the PEGA Committee’s deliberations and investigations. First, a series of PEGA Committee hearings were about to commence following the infection date, including “Big Tech and Spyware” ( October 26 ), “Spyware and e-privacy” ( October 26 ), and spyware and fundamental rights ( October 27 ). Importantly, the PEGA Committee was also in the midst of preparations for the publication of its first draft report. Drafts of the report were being discussed and circulating among PEGA Committee members and their staff in the weeks leading up to this publication. Kouloglou confirms that the first infection date (October 21, 2022) coincided with a period of intense discussion and exchange that primarily took place over text messages and email. The first draft of the PEGA Committee Report was delivered by MEP in ‘t Veld on November 8, 2022. The draft focused on allegations of spyware in Poland, Hungary, Greece, Cyprus, and Spain. In addition to the hearing and report drafting, PEGA Committee members had visited several European countries as part of their mission. Throughout October, the PEGA committee was planning its research visits to Greece and Cyprus scheduled for November 1 to 4, 2022. Kouloglou helped with planning and participated in both visits as part of the PEGA Committee deliberations. Kouloglous’ device was hacked ten days prior to the start of this trip, at a time when communications were being exchanged about the visits. Meeting with Thanasis Koukakis On October 21, 2022, the exact date of the infection, Kouloglou was in the hospital for elective surgery. He was visited in his hospital room by Greek investigative journalist Thanasis Koukakis, who has worked closely on mercenary spyware issues in Greece, and had testified to the PEGA Committee the previous month. In March 2022, the Citizen Lab had confirmed Koukakis was himself targeted with Intellexa’s Predator spyware and he was at this time pursuing legal remedies and formal complaints with relevant authorities in Greece about the spying. Koukakis memorialized his meeting with Kouloglou with a photograph ( Figure 2 ). Given that the infection took place while Kouloglou was a patient at a Greek hospital, it is possible that confidential medical information could have been intercepted from his device, including discussions going on in his room. If the spyware captured conversations between Kouloglou and medical staff, or details stored on the phone concerning appointments, medical results, diagnoses, and other health related information, then the hacking of his device may implicate Greece’s laws concerning confidentiality of health-related data, which are considered a special category of personal data and are subject to enhanced protections (Law 4624/2019 under the Greek Penal Code). Second Pegasus Infection Period: Intense PEGA Deliberations Kouloglou’s device was hacked with Pegasus spyware a second time, on March