Serbian activists, including members of a student protest movement and civil society figures, have been targeted with advanced spyware, including NSO Group's Pegasus and the locally developed NoviSpy. This surveillance campaign coincides with a period of political unrest and upcoming elections in Serbia.
The Citizen Lab, in collaboration with the SHARE Foundation, confirmed a zero-click Pegasus infection on the iPhone of a Serbian student activist. Forensic analysis traced the infection to an iMessage zero-click exploit, with high-confidence indicators of compromise identified between December 2025 and January 2026. This exploit, which required no action from the victim, allowed attackers full access to the device's data, including messages, photos, notes, microphone, and camera. Apple subsequently patched this specific exploit in iOS 18.4.1.
This confirmed Pegasus infection is part of a broader surveillance effort. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026. These targets include student movement members, civil society activists, an opposition member of parliament, and a local councilor. This wave of targeting, described by the organization as the largest documented surveillance in Serbia's history, aligns with local elections held on March 29, 2026, and precedes planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.
Twelve individuals approached SHARE's digital forensics team in August after receiving Apple Threat Notifications, which are warnings issued when Apple detects likely state-sponsored spyware targeting. Eleven of these devices are presumed infected, pending further forensic confirmation.
Beyond Pegasus, a new version of NoviSpy was discovered on an Android phone belonging to a student activist. This discovery was made by the SHARE Foundation and Amnesty Tech after Serbian authorities seized the device during police questioning. Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, linked the installation of the spyware to the period of detention by Serbian authorities.
Serbia has a documented history of using commercial spyware. Citizen Lab previously reported on Pegasus targeting civil society and the use of Cellebrite tools to install NoviSpy on activists' phones.
For individuals who receive an Apple Threat Notification, Citizen Lab advises treating it as a presumed infection and seeking expert assistance immediately. In Serbia, individuals are directed to contact the SHARE Foundation. Globally, Access Now's Digital Security Helpline supports journalists, human rights defenders, and other high-risk civil society targets. Additionally, anyone at increased risk due to their work or public role is advised to enable Apple's Lockdown Mode, which significantly reduces the attack surface for zero-click exploits, and to keep all devices updated to benefit from the latest security patches.






