A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware, as confirmed by Citizen Lab in collaboration with the SHARE Foundation. The attack leveraged an iMessage zero-click exploit, meaning the victim did not need to interact with any malicious content for the infection to occur. High-confidence indicators of Pegasus infection were identified on the device. This incident highlights the continued use of sophisticated commercial spyware against civil society members and activists. The NSO Group's Pegasus has been repeatedly linked to targeting journalists, activists, and political dissidents worldwide. The findings underscore ongoing concerns about the abuse of commercial surveillance tools against vulnerable populations.
An iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit. Citizen Lab, in collaboration with the SHARE Foundation, confirmed the infection with high-confidence indicators detected between December 2025 and January 2026. The zero-click exploit targeted Apple iMessage and required no user interaction to execute. The vulnerability was patched by Apple in iOS 18.4.1 released in April 2025. In total, at least 14 individuals in Serbia were targeted with advanced spyware since early 2026, including student movement members, activists, a member of parliament, and opposition local councilors. A separate incident involved a student movement member's Android device being compromised with a new version of NoviSpy Android spyware while the device was confiscated during police questioning. A newly discovered Android spyware strain — similar in functionality to NoviSpy but rebuilt with enhanced evasion capabilities to avoid detection by security researchers — was also found on a second Android device. Private Viber messages from that compromised device were broadcast live on Informer TV, a Serbian pro-government channel. Cellebrite forensic tools were also used in the deployment of NoviSpy on confiscated devices. The timing of the attacks coincided with local elections held on March 29, 2026.
1. Update all Apple iOS devices to iOS 18.4.1 or later immediately to patch the iMessage zero-click vulnerability used by Pegasus. 2. High-risk individuals (activists, journalists, politicians, opposition members) should enable Lockdown Mode on iOS devices to reduce attack surface. 3. Android users with high visibility or sensitive roles should enroll in Google's Advanced Protection Program to guard against targeted attacks. 4. Use WhatsApp's Strict Account Settings feature to automatically apply most restrictive settings and block attachments/media from unknown contacts. 5. Be aware of device confiscation risks — devices returned after law enforcement detention should be treated as potentially compromised and forensically examined. 6. Monitor for indicators of Pegasus infection using tools such as Citizen Lab's MVT (Mobile Verification Toolkit). 7. Avoid clicking on unexpected iMessage links or attachments, though note zero-click exploits require no user interaction. 8. Organizations supporting at-risk individuals should provide regular device security audits and threat assessments.
Pegasus spyware infection indicators on iOS (December 2025 – January 2026 timeframe), NoviSpy Android spyware (new variant with enhanced detection evasion), Unauthorized iMessage zero-click exploit activity, Private Viber messages exfiltrated and broadcast on Informer TV