Back to feed

Pegasus spyware infects Serbian student protester's iPhone via zero-click exploit

2 min
Pegasus spyware infects Serbian student protester's iPhone via zero-click exploit

This digest was compiled by AI from multiple sources — links to the originals are below.

The iPhone of a Serbian student protest movement member was infected with NSO Group's Pegasus spyware via a zero-click iMessage exploit, Citizen Lab and SHARE Foundation reported. The infection occurred between December 2025 and January 2026, and the exploit was patched by Apple in iOS 18.4.1. At least 14 people in Serbia have been targeted with advanced spyware since the start of 2026.

Key Facts

  • Citizen Lab and SHARE Foundation confirmed a zero-click iMessage exploit infected a Serbian student protester's iPhone with NSO Group's Pegasus spyware between December 2025 and January 2026.
  • Apple patched the exploited vulnerability in iOS 18.4.1, released in April 2025.
  • At least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026, including student movement members, activists, a member of parliament, and a local councilor from opposition parties.
  • Another student movement member's phone was compromised with a new version of NoviSpy Android spyware after their device was confiscated during police questioning.
  • The same spyware strain was detected on a second device after private Viber messages from that phone were disclosed live on Informer TV, a Serbian pro-government news channel.

Pegasus Infection Discovery

Citizen Lab, in collaboration with SHARE Foundation, confirmed that an iMessage zero-click exploit was used to infect the iPhone of a Serbian student protest movement member with NSO Group's Pegasus spyware. The infection indicators were found from a period across December 2025 to January 2026, though additional infections cannot be ruled out. The zero-click exploit targeted Apple iMessage and was addressed by Apple with iOS 18.4.1, released in April 2025. The discovery follows Apple sending new threat notifications to customers in 110 countries suspected of being targeted by mercenary spyware attacks.

Wider Spyware Targeting in Serbia

At least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026, according to SHARE Foundation. Targets included student movement members, activists, a member of parliament, and a local councilor from opposition parties. The timing of these incidents coincided with local elections held on March 29, 2026. Another student movement member's phone was compromised with a new version of NoviSpy Android spyware after their device was confiscated during police questioning. Amnesty International's Security Lab head Donncha Ó Cearbhaill stated that Serbian students continue to be targeted with invasive Android spyware tools installed while detained by Serbian authorities.

New Android Spyware Strain

The latest 2026 case revealed a new Android spyware similar in functionality to NoviSpy but newly built with specific efforts to avoid detection by security experts. SHARE detected the same spyware strain on a second device after private Viber messages from that phone were disclosed live on Informer TV, a Serbian pro-government news channel. The development is the latest in a string of documented abuses of surveillance technology in Serbia, including the use of Cellebrite forensic tools to deploy NoviSpy.