
A member of Serbia’s pro-democracy student movement was infected with NSO Group’s Pegasus spyware through a zero-click iMessage exploit.
The case is part of a broader surveillance wave that has targeted at least 14 students, activists and opposition politicians since the beginning of 2026.
Citizen Lab examined the student’s iPhone after the individual received an Apple Threat Notification warning that they had been targeted with mercenary spyware. Researchers found high-confidence indicators of Pegasus infection activity between December 2025 and January 2026, although they could not rule out additional infections.
According to Citizen Lab senior researcher Bill Marczak, the attack used a zero-click exploit targeting Apple’s iMessage service, meaning the victim did not need to click a link or take any other action. Citizen Lab believes Apple subsequently neutralized the exploit with security changes included in iOS 18.4.1.
Pegasus is commercial surveillance software developed by Israeli firm NSO Group and sold to government customers. Once deployed, it can provide extensive access to a compromised smartphone, including messages, photographs, notes and other stored data, while also allowing operators to covertly activate its microphone and camera.
The SHARE Foundation says at least 14 people associated with Serbia’s student movement, civil society and political opposition have been targeted with advanced spyware since early 2026, describing it as the country’s largest documented surveillance wave to date. Targets include a member of parliament and a local councilor, with the activity coinciding with Serbia’s March 29, 2026 local elections.
Twelve people approached SHARE’s digital forensics team in August after receiving Apple spyware warnings. Eleven additional devices remain presumed targeted based on those notifications, while forensic investigations continue with Citizen Lab and Amnesty International’s Security Lab.
The investigation also uncovered a new version of NoviSpy on the Android phone of another student activist whose device had previously been confiscated during police questioning. Amnesty Security Lab head Donncha Ó Cearbhaill said the newly identified spyware is functionally similar to NoviSpy but appears to have been rebuilt with measures intended to make it harder to detect.
The same malware was discovered on another device after private Viber messages from the phone were disclosed on Serbia’s TV Informer, according to SHARE.
The findings extend an established pattern of invasive phone surveillance in Serbia. In 2024, Amnesty researchers uncovered NoviSpy on phones seized during police interviews, with stolen data sent to infrastructure linked to Serbia’s Security Information Agency (BIA). Our previous coverage also documented how Serbian authorities used Cellebrite forensic technology and Android zero-day vulnerabilities to unlock a detained student activist’s phone before attempting to install spyware.
Unlike Pegasus, which can compromise an iPhone remotely, NoviSpy infections documented in Serbia have required physical access to targeted devices.
People who receive an Apple Threat Notification should treat the warning as a serious indication of attempted spyware compromise and seek expert forensic assistance. High-risk users should also keep operating systems fully updated and enable protections such as Apple’s Lockdown Mode or Android’s Advanced Protection features. Close contacts of confirmed targets may also warrant screening, as compromised devices can expose communications involving colleagues, family members, and other associates.







Leave a Reply