A member of Serbia’s student protest movement was infected with the Pegasus spyware through a zero-click exploit targeting Apple’s iMessage, an investigation by Citizen Lab and the SHARE Foundation has revealed. The firm confirmed “high-confidence indicators” of infection between December 2025 and January 2026, though they noted that additional infections in other timeframes aren’t ruled out. The exploit was addressed by Apple in its iOS 18.4.1 update, released in April 2025.
Scope of the Targeting
At least 14 individuals in Serbia have fallen victim to advanced spyware tools since the start of 2026, according to the SHARE Foundation. Those targeted include student movement members, activists, opposition politicians and a local councilor. One case involved Android spyware, referred to as NoviSpy, which was installed after the victim’s phone was confiscated during police questioning.
Weaponization and Response
The attack exploited a zero-click vulnerability in iMessage, meaning the victim didn’t need to interact with a malicious message. The version of Pegasus used in this spyware attack mirrors others tied to NSO Group that have exploited iOS vulnerabilities in the past. Apple patched the specific exploit in iOS 18.4.1, months before the infections took place.
Alongside iPhone cases, there’s evidence of a newly built Android spyware strain with similarities to existing NoviSpy tools but designed to bypass detection by security analysts. One Android-based infection was discovered when Viber messages were publicly disclosed live on a pro-government media channel in Serbia, from a device compromised by this strain.
Authorities in Serbia are also implicated: in certain incidents, spyware was installed during detentions. SHARE and Amnesty International’s Security Lab highlighted concerns that state actors may be abusing forensic tools, including Cellebrite, to deploy surveillance software like NoviSpy.
Protective advice from the share lab: keep all devices patched, enable iOS Lockdown Mode where available, and for Android users with heightened exposure, enroll in programs like Google’s Advanced Protection. Meta’s WhatsApp has also added Strict Account Settings to harden against targeted cyberattacks, by limiting attachments and media from unknown contacts and enforcing tighter privacy defaults.
This case underscores the persistent danger posed by mercenary spyware, especially in nations undergoing political flux. Even when significant vulnerabilities are patched, zero-click exploits can pose risks long past fixes—since attackers may exploit unpatched devices or evolve new strains. For those in civil society, transparency and oversight over state surveillance are becoming as critical as software security. Going forward, monitoring forensic tool usage and ensuring public awareness are key to countering misuse of spyware.