The iPhone belonging to a member of Serbia’s scholar protest motion was contaminated with NSO Group’s Pegasus spyware, in response to new findings from the Citizen Lab in collaboration with the SHARE Basis.
“Our evaluation confirmed that an iMessage zero-click exploit was used to contaminate the system with NSO Group’s Pegasus spyware and adware,” the Citizen Lab said. “We discovered high-confidence indicators of an infection from a interval throughout December 2025 – January 2026; nonetheless, this doesn’t preclude the potential for further infections.”
It is assessed that the zero-click exploit used within the assault focused Apple iMessage, and has been addressed by Apple with iOS 18.4.1, which was launched in April 2025.
The invention comes within the aftermath of Apple sending a brand new set of menace notifications to clients whom it suspected might have been focused by mercenary spyware and adware assaults. The alerts have been despatched to an unspecified variety of customers in 110 international locations.
In all, no less than 14 individuals in Serbia have been focused with superior spyware and adware because the starting of 2026, the SHARE Basis confirmed. Amongst these focused have been scholar motion members, activists, a member of parliament, and an area councilor from opposition events.
The timing of those incidents coincided with the native elections held on March 29, 2026. One other scholar motion member had their cellphone compromised with a brand new model of the NoviSpy Android spyware and adware after their system was confiscated throughout police questioning.
“The forensic findings by SHARE show that Serbian college students proceed to be focused with invasive Android spyware and adware instruments, put in whereas detained by Serbian authorities,” Donncha Ó Cearbhaill, head of Amnesty Worldwide’s Safety Lab, mentioned.
“The most recent 2026 case additionally reveals a brand new Android spyware and adware, comparable in performance to NoviSpy, however newly constructed with particular efforts taken to keep away from detection by safety consultants.”
SHARE mentioned the identical spyware and adware pressure has been detected on a second system, after personal Viber messages from that cellphone have been disclosed dwell on Informer TV, a Serbian pro-government information and media tv channel.
The event is the newest in a string of documented abuses of surveillance know-how within the nation, together with the usage of Cellebrite forensic instruments to deploy NoviSpy.
Customers who’re in danger due to who they’re and what they do ought to preserve the units up-to-date and take into account enabling Lockdown Mode on iOS. Google additionally gives an Advanced Protection Program to safeguard Android customers with excessive visibility and delicate data from focused on-line assaults.
Earlier this 12 months, Meta-owned WhatsApp announced a function referred to as Strict Account Settings to guard customers in opposition to superior cyber assaults by routinely locking sure settings to probably the most restrictive choices, whereas blocking attachments and media from individuals not in a person’s contact checklist.
