The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers at Citizen Lab and the SHARE Foundation confirmed that a member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware through a zero-click iMessage exploit, with infection indicators from December 2025 to January 2026.
- At least 14 people in Serbia, including student activists, a member of parliament, and opposition politicians, have been targeted with advanced spyware since early 2026, around the time of local elections in March 2026.
- Another student's phone was infected with a new version of the NoviSpy Android spyware while in police custody, and the same spyware strain was found on a second device whose Viber messages were broadcast on a pro-government TV channel.
- The findings point to continued use of surveillance tools against activists in Serbia, and users at risk are advised to keep devices updated and enable protective modes like Apple's Lockdown Mode or Google's Advanced Protection Program.
What to watch next
- Whether Apple's iOS 18.4.1 fix, which addressed the iMessage exploit, prevents further Pegasus infections in Serbia
- Possible disclosure of who is behind the spyware campaigns targeting Serbian students and opposition figures
- Further forensic findings on the newly discovered Android spyware variant and additional affected devices
Coverage1
1 report
English national1
All filed from India
Named Serbia · Apple · Meta · WhatsApp · Amnesty International · Citizen Lab · Informer TV · NSO Group · SHARE Foundation
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
