AI generated image
At least 14 people connected to Serbia’s student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country.
The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at the University of Toronto and by Amnesty International’s Security Lab.
Citizen Lab, in its own findings, said it verified an infection with NSO Group’s Pegasus on the iPhone of a student activist who asked not to be named. High-confidence infection indicators span December 2025 through January 2026, delivered by a zero-click iMessage exploit that required no interaction from the target. Apple has since patched the underlying flaw; the fix shipped in iOS 18.4.1. Pegasus grants an operator access to notes, photographs and messages decrypted on the device, and can silently activate the microphone and camera.
Amnesty’s Security Lab confirmed a new variant of NoviSpy, an Android implant first identified in Serbia in 2024, on two additional devices. SHARE said the rebuilt version was designed to evade the detection methods that exposed its predecessor.
The circumstances of two infections are what elevate the findings beyond routine spyware reporting. SHARE said one NoviSpy infection appeared after police seized a student’s phone during questioning, and another after private messages from that device were published by a pro-government media outlet. Donncha Ó Cearbhaill, who heads Amnesty’s Security Lab, said the evidence suggests “infections are being carried out during detention by Serbian authorities.”
Suspicion centers on Serbia’s Security Information Agency, or BIA. Amnesty’s December 2024 report “A Digital Prison” found earlier NoviSpy samples configured to send collected data to IP addresses associated with BIA servers, and documented the agency’s parallel use of Cellebrite extraction tools on journalists and activists. In March 2025, Amnesty reported that two journalists at the Balkan Investigative Reporting Network were targeted with Pegasus.
The current cases surfaced through Apple’s threat notification wave of Aug. 13, which reached users in 110 countries. The timing is politically loaded. The targeting overlaps with protests that followed the November 2024 collapse of a railway station canopy in Novi Sad, spans local elections held March 29 in 10 municipalities, and precedes October parliamentary elections widely read as a test of the ruling Serbian Progressive Party.
Ana Toskic Cvetinovic, a legal expert cited in the reporting, noted that deploying intrusive software without judicial authorization is unlawful under Serbian law. SHARE published an analysis of the domestic legal framework in January arguing the same. Criminal complaints filed over the 2024 cases remain pending before Serbian courts, with no resolution.
NSO has been on the U.S. Commerce Department’s Entity List since 2021.
Serbia is an accession candidate, the European Parliament has previously questioned the Commission over unlawful spyware use in the country, and the Commission published its 2026 enlargement country report in July. Amnesty’s submission for that package raised surveillance directly.
Both groups urged at-risk users to enable Lockdown Mode on iOS or Advanced Protection on Android.
This week’s cybersecurity roundup covers Claude session hijacking, PaperCut exploits, Boston Scientific’s cyberattack, X account attacks, and Citrix flaws.
CBI searched 89 locations across 20 states in three digital arrest cases under Operation Chakra-VI, arresting three accused of laundering…
Kentucky Appellate Court data was compromised in a third-party C-Track breach. The AOC says the investigation continues and affected parties…
For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions and…
CVE-2026-84115 affects Cleo Harmony through version 5.8.1.10, with a JWT Refresh Token Handler flaw enabling remote privilege escalation.
SonicWall says attackers are chaining two SMA1000 zero-days, including a CVSS 10.0 pre-auth SSRF flaw, for remote code execution. Emergency…
This website uses cookies. By continuing to use this website you are giving consent to cookies being used.
Read More