Pegasus Spyware Found on Serbian Activist's iPhone, New Android Strain Discovered
A prominent Serbian student protest movement member's iPhone was infected with **NSO Group**'s **Pegasus** spyware, utilizing an **iMessage** zero-click exploit. This discovery, made by **Citizen Lab** and the **SHARE Foundation**, highlights a broader pattern of targeted surveillance against activists and opposition figures in Serbia, coinciding with local elections.

New findings from **Citizen Lab**, in collaboration with the **SHARE Foundation**, confirm that an **iPhone** belonging to a member of Serbia's student protest movement was compromised with **NSO Group**'s **Pegasus** spyware.
### Zero-Click Exploit Targets iMessage
The analysis revealed that an **iMessage** zero-click exploit was used to infect the device. **Citizen Lab** stated, "Our analysis confirmed that an **iMessage** zero-click exploit was used to infect the device with **NSO Group**'s **Pegasus** spyware." High-confidence indicators of infection were identified from December 2025 to January 2026.
This specific zero-click exploit is believed to have been addressed by **Apple** with the release of **iOS 18.4.1** in April 2025.
### Broader Surveillance Campaign
The revelation follows **Apple**'s recent issuance of threat notifications to users in 110 countries suspected of being targeted by mercenary spyware. The **SHARE Foundation** has confirmed that at least 14 individuals in Serbia, including student movement members, activists, a member of parliament, and a local councilor, have been targeted with advanced spyware since early 2026.
These incidents align with the local elections held on March 29, 2026.
### New Android Spyware Emerges
In a separate but related incident, another student movement member's phone was compromised with a new version of the **NoviSpy** Android spyware. This occurred after their device was confiscated during police questioning.
**Donncha Γ Cearbhaill**, head of **Amnesty International**'s Security Lab, noted, "The forensic findings by **SHARE** prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities." He added that the latest 2026 case reveals a new Android spyware, similar to **NoviSpy**, engineered with specific efforts to evade detection.
The same spyware strain was also detected on a second device, from which private **Viber** messages were subsequently disclosed on **Informer TV**, a pro-government Serbian news channel. This underscores a troubling pattern of surveillance technology abuse in the country, including the use of **Cellebrite** forensic tools to deploy **NoviSpy**.
### Recommendations for High-Risk Users
For users at heightened risk due to their public profile or activities, keeping devices up-to-date and enabling **Lockdown Mode** on **iOS** are crucial steps. **Google** also offers its **Advanced Protection Program** to safeguard high-visibility Android users with sensitive information.
Earlier this year, **Meta**-owned **WhatsApp** introduced **Strict Account Settings**, a feature designed to protect users against advanced cyberattacks by automatically applying the most restrictive privacy options and blocking attachments from non-contacts.