An iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to a new investigation by the Citizen Lab in collaboration with the SHARE Foundation.
Researchers found evidence that an iMessage zero-click exploit was used to compromise the device. Zero-click exploits are particularly dangerous because they can infect a device without requiring the victim to click a malicious link, open an attachment, or otherwise interact with the attack.
“Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” Citizen Lab said.
The investigation identified high-confidence indicators of Pegasus infection between December 2025 and January 2026, although researchers said the findings do not rule out the possibility of additional infections.
Pegasus Attack Exploited Apple iMessage
According to Citizen Lab’s analysis, the exploit used in the attack targeted Apple’s iMessage platform.
Researchers believe Apple addressed the underlying vulnerability with the release of iOS 18.4.1 in April 2025. The discovery highlights the importance of keeping devices updated, particularly for individuals who may be targeted because of their political activities, journalism, activism, or other high-profile work.
The findings emerged shortly after Apple sent a new round of threat notifications to customers it suspected may have been targeted by mercenary spyware. The notifications were reportedly sent to users across 110 countries.
At Least 14 People Targeted in Serbia
The Pegasus infection is part of a broader pattern of suspected spyware targeting in Serbia.
According to the SHARE Foundation, at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026.
Those targeted reportedly include:
- Members of the student protest movement
- Activists
- A member of parliament
- A local councilor affiliated with an opposition party
The incidents coincided with local elections held on March 29, 2026, adding to concerns about the potential use of intrusive surveillance technology against politically active individuals.
Another Student Targeted With Android Spyware
The investigation also uncovered another case involving a member of Serbia’s student movement.
In that incident, the individual’s Android phone was reportedly compromised with a new version of the NoviSpy spyware after the device was confiscated during police questioning.
Amnesty International’s Security Lab said forensic evidence indicated that Serbian students continue to face the use of invasive Android spyware while in detention.
“The latest 2026 case also reveals a new Android spyware, similar in functionality to NoviSpy, but newly built with specific efforts taken to avoid detection by security experts,” said Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab.
New Spyware Linked to Leaked Viber Messages
The SHARE Foundation said the same spyware strain was also discovered on a second device.
According to the organization, private Viber messages from that device were subsequently disclosed live on Informer TV, a Serbian pro-government television and media outlet.
The development raises additional concerns over the potential use of commercial spyware not only for device surveillance but also for obtaining and exposing private communications.
Growing Concerns Over Surveillance Technology in Serbia
The latest findings add to a growing body of evidence documenting the alleged misuse of surveillance technology in Serbia.
Previous investigations have linked the use of Cellebrite forensic tools to the deployment of NoviSpy, an Android spyware platform used to monitor targeted individuals.
The repeated targeting of activists and members of the student protest movement has raised concerns among digital-rights and cybersecurity organizations about the use of sophisticated surveillance capabilities against civil society.
How High-Risk Users Can Protect Their Devices
Individuals who may be targeted because of their identity, profession, political activity, or access to sensitive information should take additional security precautions.
Keeping operating systems and applications fully updated is one of the most important steps users can take because security updates often address vulnerabilities that could otherwise be exploited by sophisticated attackers.
iPhone users who face an elevated risk of targeted spyware attacks should also consider enabling Lockdown Mode, Apple’s security feature designed to reduce the attack surface of highly targeted devices.
Android users with high visibility or access to sensitive information can consider Google’s Advanced Protection Program, which provides additional safeguards against targeted online attacks.
Meta-owned WhatsApp has also introduced Strict Account Settings, a feature designed to protect users against advanced cyberattacks by automatically applying more restrictive security settings and blocking attachments and media from people who are not in a user’s contacts.
Spyware Threat Continues to Grow
The discovery of Pegasus on an iPhone belonging to a Serbian student protester demonstrates the continuing threat posed by commercial spyware.
Unlike conventional malware, advanced spyware such as Pegasus is designed to operate covertly and can exploit sophisticated vulnerabilities to gain access to sensitive communications and device data.
The combination of zero-click attacks, increasingly difficult-to-detect Android spyware, and the targeting of activists and political figures underscores the need for stronger device security and rapid patching.
For people at elevated risk, security experts recommend keeping devices updated, minimizing unnecessary applications and services, using strong account protections, and enabling specialized security features such as Apple’s Lockdown Mode when appropriate.
