Illustrative image generated with AI
Pegasus and NoviSpy Used Against Serbian Students: Zero-Click iPhone Attack Confirmed
Citizen Lab confirmed Pegasus zero-click iPhone infection via iMessage against Serbian student amid wider surveillance of activists with NoviSpy.
Text generated by artificial intelligence, published without human review. AI transparency
A member of Serbia’s student movement was infected with Pegasus through an iMessage zero-click exploit. The attack did not require the victim to open an attachment, click a link, or reply to a message: all it took was for the malicious content to reach the device.
Citizen Lab confirmed the compromise by examining forensic artefacts from the iPhone together with the SHARE Foundation. The analysis began after Apple warned the owner of a possible mercenary spyware attack.
The indicators of compromise were placed with high confidence between December 2025 and January 2026. The recently reported case appears to be part of a much broader campaign targeting Serbian students, activists, and opposition representatives.
Apple’s warning followed by forensic confirmation
Apple Threat Notifications are intended for users who, according to the company’s systems, may have been targeted by mercenary spyware operators associated with state-sponsored activity. They are not generic warnings and do not indicate an ordinary malware infection.
Receiving a notification, however, does not by itself prove that a phone has been compromised. A forensic analysis is needed to reconstruct the processes, files, logs, and other traces left by the exploit or spyware.
In the Serbian student’s case, that examination produced a confirmation: the device contained indicators consistent with a Pegasus infection. Citizen Lab did not rule out additional compromises, but their number was not determined.
The iPhone model, the iOS version installed at the time of the attack, and the exploit’s technical identifier were not disclosed. As a result, it is impossible to establish the full range of vulnerable versions. It is known, however, that Apple neutralized the specific vector with patches released starting with iOS 18.4.1.
No CVE identifier associated with the exploit has been disclosed. There is also no information about whether it was added to CISA’s KEV Catalog.
At least 14 people targeted since the beginning of 2026
The SHARE Foundation has documented at least 14 people targeted in advanced spyware operations since the beginning of 2026. The targets belong to politically sensitive groups:
- members of the student movement;
- civil society activists;
- an opposition member of parliament;
- a local councilor.
Twelve people contacted the foundation’s digital forensics team in August after receiving Apple Threat Notifications. Eleven devices remain classified as potentially infected and require further investigation.
This distinction is essential. So far, the Pegasus infection confirmed through forensic analysis concerns one iPhone; the other warnings indicate a concrete risk but do not automatically amount to eleven proven compromises.
According to the SHARE Foundation, this is the largest documented surveillance wave in Serbia’s history. The choice of targets suggests an operation built around the protest movement’s political and organizational relationships, rather than an indiscriminate campaign.
Compromising even one member of a network can expose many others. Messages, contacts, calendars, photographs, and communication histories can reveal an organization’s contacts, meetings, sources, and internal structures.
How a zero-click iMessage infection works
Zero-click attacks exploit components that automatically process received data. In the case examined, the attack surface was iMessage: the system could process the malicious content without the recipient opening or interacting with it.
This removes one of the main warning signs users can recognize. There may be no suspicious link to identify, unusual attachment to avoid, or credential request to reject.
Once installed, Pegasus can allow an operator to extract messages, photographs, notes, and other data stored on the phone. It can also access content the user considers protected by encryption because the spyware operates directly on the device where that information is displayed or created.
Pegasus is also capable of secretly activating the microphone and camera. The smartphone can therefore become an environmental sensor, allowing the operator to listen to conversations or observe what is happening around the victim.
The absence of visible symptoms does not mean that a device is safe. Spyware in this class is designed to minimize operational traces, avoid obvious notifications, and limit behavior that could arouse the owner’s suspicion.
NoviSpy found on a seized Android phone
Pegasus is not the only tool to emerge from the investigations. In a separate incident, the SHARE Foundation and Amnesty Tech identified a new version of NoviSpy on the Android phone of a student activist.
Serbian authorities had seized the device during a police interrogation. The available forensic details indicate that the spyware may have been installed while the phone was under the authorities’ control.
The device model, the Android version involved, and a complete list of the new variant’s capabilities were not disclosed. NoviSpy is described as spyware developed locally.
Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, linked the findings to the continuation of surveillance campaigns against students. The case differs technically from the Pegasus attack: here, the possible vector was not a remote zero-click exploit but physical access to a seized phone.
This would not be an isolated precedent. Citizen Lab had previously documented the use of Cellebrite tools in Serbia to access devices and install NoviSpy on activists’ phones. Cellebrite and NoviSpy serve distinct roles: the former can facilitate access to the device, while the latter carries out the subsequent surveillance.
A campaign amid intensifying political tensions
The operations took place during student protests against the government and corruption. The documented incidents also cover the period around the local elections on March 29, 2026, and precede the early parliamentary elections expected in October.
The combination of targets is significant. Students, activists, local representatives, and opposition members share a political profile that can make their internal communications particularly valuable.
The available data do not publicly identify the individual operator responsible for the Pegasus infection. Apple notifications indicate likely state-sponsored mercenary spyware activity, but the attack’s technical and institutional attribution has not been disclosed.
Serbia has previously recorded cases involving the use of Pegasus against civil society figures. The new incident therefore fits into a series of documented operations, alongside the local use of NoviSpy.
Updates, Lockdown Mode, and forensic assistance
Apple users should install the latest updates on all their devices. The specific iMessage exploit observed in the attack was fixed in updates included in iOS 18.4.1 and later versions.
For journalists, politicians, activists, and human rights defenders facing targeted risks, Apple also recommends Lockdown Mode. This feature reduces the attack surface available to exploits by limiting certain messaging, browsing, and communication features.
Anyone who receives an Apple Threat Notification should treat the phone as potentially compromised. Immediately resetting the device or deleting its contents can destroy evidence useful to an investigation; before taking action, it is preferable to seek specialized assistance and preserve the evidence.
In Serbia, the designated contact is the SHARE Foundation. In other countries, high-risk civil society members can contact Access Now’s Digital Security Helpline.
The priority is not to look for slowdowns, unusual battery drain, or unfamiliar applications. In a professional zero-click attack, these signs may not appear at all. A targeted Apple warning instead requires a rapid, coordinated, and forensic response.
Sources
This article is an original reworking based on the sources below.
