A member of Serbia's student protest movement has fallen victim to the notorious Pegasus spyware, as reported by Citizen Lab in collaboration with the SHARE Foundation. The spyware, developed by NSO Group, infiltrated the activist's iPhone using a zero-click exploit via Apple’s iMessage. The infection was confirmed to have occurred between December 2025 and January 2026, although there may have been additional infections beyond this period. Apple has addressed the vulnerability with the release of iOS 18.4.1 in April 2025, but the revelation highlights ongoing risks. The incident is part of a broader pattern of surveillance in Serbia, with at least 14 individuals, including student activists, politicians, and local councilors from opposition parties, targeted since early 2026. These attacks coincided with the local elections held in March. In another case, a student’s Android phone was compromised with NoviSpy spyware after police detention. Further analysis by SHARE and Amnesty International has identified new Android spyware, akin to NoviSpy, that is designed to evade detection. This strain has been linked to a second device, with private messages being leaked on Serbian television. This ongoing surveillance underscores the abuse of technology in Serbia, including the use of forensic tools like Cellebrite. To counteract these threats, at-risk users are advised to keep devices updated and consider using security features such as iOS Lockdown Mode or Google’s Advanced Protection Program. Additionally, WhatsApp has introduced Strict Account Settings to mitigate the risk of advanced cyber attacks by restricting certain settings and blocking unknown media.
Pegasus Spyware Targets Serbian Activists in Zero-Click Attack
NSO Group Pegasus used an iMessage zero-click exploit to infect a Serbian student activist's iPhone enabling remote surveillance.


