Pegasus Spyware Targets Serbian Student Activist Through IMessage Zero Click Exploit

Pegasus Spyware Targets Serbian Student Activist Through IMessage Zero Click Exploit

Citizen Lab, working in collaboration with the SHARE Foundation, has confirmed that the iPhone of a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware through a zero click exploit targeting Apple iMessage. According to the forensic investigation, the compromise occurred without any interaction from the device owner and showed high confidence indicators of infection during the period between December 2025 and January 2026. Researchers noted that while this timeframe was confirmed through forensic evidence, additional infections outside that period could not be ruled out. The exploit is believed to have targeted Apple iMessage and has since been addressed by Apple through the release of iOS 18.4.1. The findings were disclosed shortly after Apple issued threat notifications to an unspecified number of users across 110 countries, warning that they may have been targeted by mercenary spyware attacks.

The investigation also revealed that the incident forms part of a wider pattern of surveillance activity in Serbia. According to the SHARE Foundation, at least 14 individuals have been targeted with advanced spyware since the beginning of 2026. Those affected include members of the student protest movement, activists, a member of parliament, and a local councilor representing opposition parties. Researchers noted that many of these incidents occurred around the time of Serbia’s local elections held on March 29, 2026. In a separate case, another student movement member reportedly had an Android device compromised with a newer version of NoviSpy after the phone was confiscated during police questioning. Amnesty International’s Security Lab stated that forensic findings indicate Serbian students continue to face targeted surveillance using sophisticated Android spyware installed while devices were in official custody. Researchers also identified a newly developed Android spyware variant that shares functionality with NoviSpy while incorporating measures intended to reduce detection by security analysts.

Further analysis by the SHARE Foundation identified the same spyware strain on a second Android device after private Viber messages from that phone were publicly disclosed during a live television broadcast on Informer TV, a Serbian pro government media outlet. The latest findings add to previously documented cases involving surveillance technologies within the country, including earlier reports concerning the use of Cellebrite forensic tools in connection with NoviSpy deployments. Researchers said these incidents demonstrate the continued evolution of commercial spyware and surveillance capabilities that can affect activists, journalists, political figures, and other individuals considered at higher risk of targeted cyber activity. The investigation also highlights how zero click exploits remain particularly concerning because they require no action from the device owner to compromise a system.

Security researchers recommend that individuals who may face elevated cyber risks keep their devices updated with the latest security patches and enable additional protections where available. Apple advises users with higher exposure to targeted attacks to activate Lockdown Mode on supported iOS devices, while Google provides its Advanced Protection Program to strengthen security for Android users handling sensitive information. Earlier this year, WhatsApp also introduced a feature called Strict Account Settings that automatically applies more restrictive security controls, including blocking media and attachments from people outside a user’s contact list. Researchers said these security measures can help reduce exposure to advanced spyware attacks, although regular software updates and layered security practices remain important for protecting devices against evolving threats.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment