Pegasus Spyware in Serbia Targets Student Activist
TL;DR
Researchers at the Citizen Lab and the SHARE Foundation confirmed a mercenary spyware attack in Serbia. A zero-click exploit delivered Pegasus spyware to an iPhone belonging to a pro-democracy student activist. Meanwhile, independent forensic analysis revealed that at least 14 civil society figures and opposition politicians faced similar state surveillance.
Delivery
In August 2026, twelve people in Serbia contacted digital forensics experts after receiving Apple Threat Notifications on their phones. Soon after, the SHARE Foundation documented at least 14 targeted individuals across Serbia’s student movement and political opposition. These warnings alerted users that government-backed attackers had targeted their devices with commercial surveillance tools.
Forensic investigators found that the primary attack vector relied on Apple iMessage. Specifically, the threat actor delivered Pegasus spyware without requiring any action from the target. The zero-click exploit functioned completely in the background. Therefore, the victim never received a suspicious link or an unusual prompt.
The SHARE Foundation published details in their investigation into targeted students and opposition politicians. Separately, investigators documented a different delivery vector targeting Android users in Serbia. In those cases, police officers confiscated phones during questioning and installed a new version of NoviSpy spyware. Authorities used digital forensics extraction hardware to place the malicious software directly onto the seized hardware.
Infection Chain
The iOS exploit chain compromised devices running outdated versions of Apple operating systems. Citizen Lab researchers determined that the attackers weaponized a flaw in iMessage processing. The exploit executed within the messaging application environment. Then, it bypassed operating system sandboxes to gain root privileges on the device.
Apple resolved the underlying vulnerability in the iOS 18.4.1 release. As a result, devices that remain unpatched past that version remain vulnerable to the exploit. Citizen Lab confirmed the technical details in their forensic analysis of the Pegasus spyware infection.
Bill Marczak, Senior Researcher at The Citizen Lab, emphasized the timing of the breach. Marczak stated, “We confirmed that the student’s device was hacked with a Pegasus zero-click exploit across December 2025-Jan 2026.” The forensic timeline shows that the intrusion occurred weeks ahead of key local elections in Serbia.
John Scott-Railton, Senior Researcher at The Citizen Lab, highlighted the political context. Scott-Railton stated, “Our forensic findings, and this fresh wave of Apple Threat Notifications reveal that Serbia’s peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles.”
Command-and-Control and Data-Exfiltration Behaviour
Once installed, Pegasus spyware provides complete control over the infected mobile device. The operator can access private photo libraries, personal notes, call logs, and browser histories. Furthermore, the malware reads messages from encrypted messaging applications like Signal, WhatsApp, and Telegram.
It can also activate the phone’s microphone and camera without alerting the owner. This capability turns the smartphone into a covert listening device. The spyware exfiltrates collected records over encrypted HTTPS connections to proxy servers. NSO Group leases this infrastructure directly to government clients.
In the NoviSpy cases, stolen data traveled directly to servers belonging to Serbia’s Security Information Agency. Donncha O Cearbhaill, Head of Amnesty International’s Security Lab, addressed the dual-platform threat. O Cearbhaill stated, “The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities.” He added that the latest variant was “newly built with specific efforts taken to avoid detection by security experts.”
Defense or Detection Guidance
Apple users facing heightened surveillance risks must protect their devices immediately. First, users should install all available operating system updates promptly. Keeping software updated patches known zero-click vulnerabilities in core applications. Apple provides step-by-step instructions on how to keep your iPhone updated to recent releases.
In addition, high-risk individuals should enable specialized protection features on their hardware. Users can activate Lockdown Mode on their iPhone to block complex message attachments. Lockdown Mode restricts browser technologies and blocks incoming connection requests from unknown callers.
Recipients of official threat alerts should treat their devices as presumed infected. Civil society members should contact organizations like the SHARE Foundation or Access Now for forensic verification. Finally, organizations must establish emergency incident response plans to assist staff facing state surveillance.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.