Breaking
Cyber CrimeDeveloping Story

Pegasus iMessage Attack Targets Serbian Student Activist

Citizen Lab finds NSO Group spyware on an activist's iPhone via a zero-click exploit, highlighting ongoing surveillance of Serbian civil society.

··2 hours ago·3 min read
silver Android smartphone
Photo by Rami Al-zayat on Unsplash

A forensic investigation by the Citizen Lab and the SHARE Foundation has uncovered a Pegasus spyware infection on the iPhone of a member of Serbia's student protest movement, delivered through an iMessage zero-click exploit. The finding, published on September 2, 2026, adds to a pattern of surveillance targeting civil society in Serbia, with implications for activists and journalists worldwide.

Zero-Click Infection Details

According to the Citizen Lab, the attack exploited an iMessage vulnerability that the organization believes was patched by Apple in iOS 18.4.1, released in April 2025. The exploit required no action from the target, meaning the infection could occur without the recipient clicking a link or opening an attachment.

The researchers noted that such an infection would have been invisible to the target, providing the attacker with total access to the device. This includes access to notes, pictures, and encrypted messages, as well as the ability to covertly activate the microphone and camera without the user's knowledge.

Investigation and Notification

The Citizen Lab said the investigation began after the individual received an Apple Threat Notification warning of targeting with mercenary spyware. The notification was among at least 14 documented by the SHARE Foundation involving members of Serbia's student movement and civil society, as well as an opposition member of parliament.

According to the research, the targeting occurred ahead of key 2026 election cycles in Serbia. The infected individual consented to publication but asked to remain unnamed, and the exact infection date was withheld to protect their privacy. The Citizen Lab reported high-confidence indicators of infection across December 2025 and January 2026, but noted this did not rule out further infections.

Context of Surveillance in Serbia

The Citizen Lab, based in Toronto, said this case is part of a longer history of surveillance abuses in Serbia. This includes previous Pegasus targeting of civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware. The same day, the SHARE Foundation and Amnesty Tech confirmed that a new version of NoviSpy had been found on another student movement member's device.

This ongoing pattern suggests that Serbian authorities or their allies are actively using commercial spyware to monitor activists and perceived political opponents, raising concerns about the extent of such surveillance.

Key Statistics and Dates

  • At least 14 Apple Threat Notifications documented by the SHARE Foundation involving Serbian student movement and civil society members.
  • Infection detected across December 2025 and January 2026.
  • iOS 18.4.1, released in April 2025, patched the exploit used.
  • Research published September 2, 2026.

Recommendations for Notification Recipients

The Citizen Lab advised that receiving an Apple Threat Notification should be treated as a presumption of infection, urging recipients to seek expert assistance immediately. This guidance underscores the seriousness of such warnings, which are typically only sent to individuals who have been targeted by sophisticated spyware like Pegasus.

The researchers also recommended that close contacts of the target, including family members and collaborators, undergo spyware screening. They advised that individuals at heightened risk enable Apple's Lockdown Mode and keep all devices updated to the latest software versions.

Resources for Affected Individuals

For individuals in Serbia, the Citizen Lab encouraged contacting the SHARE Foundation for assistance. Recipients of notifications in other regions were directed to trusted experts such as Access Now's Digital Security Helpline. The organization pointed to online resources including Security Planner, though it emphasized the importance of personalized advice.

The Citizen Lab said its forensic work on the other notification cases was continuing. The confirmation of this infection demonstrates continued targeting of Serbia's pro-democracy movement with mercenary spyware, even as the lab works to identify and assist other victims.

Why It Matters

This case illustrates the high stakes for journalists, activists, and dissidents who rely on mobile devices for communication and organization. Zero-click exploits like the one used in this attack are particularly dangerous because they require no user interaction, making them difficult to detect and defend against, even for technically savvy individuals.

The fact that the Citizen Lab believes the vulnerability was patched in April 2025 suggests that timely software updates are a critical defense, but the infection occurred later, indicating that the target may not have updated promptly. This underscores the challenge of ensuring that at-risk individuals maintain up-to-date software, especially in environments where targeted surveillance is prevalent.

Commercial spyware like Pegasus continues to be used against civil society, raising questions about the accountability of spyware vendors and the effectiveness of international regulations. As forensic investigations uncover more cases, the pressure grows on both governments and technology companies to address these threats and protect vulnerable populations.

#pegasus#nso group#spyware#serbia#zero-click#citizen lab

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories