Pegasus found on Serbian student movement member’s iPhone

Citizen Lab, working with Serbia’s SHARE Foundation, confirmed that the iPhone of a member of the country’s student protest movement was infected with NSO Group’s Pegasus spyware through an iMessage zero-click exploit. The organisations found high-confidence indicators of compromise spanning December 2025 to January 2026, while noting that additional infections cannot be ruled out.
The exploit is assessed to have targeted Apple iMessage. Apple addressed the vulnerability with iOS 18.4.1, released in April 2025. The finding emerged after Apple issued a new round of threat notifications to customers it suspected may have been targeted by mercenary spyware attacks; those alerts reached an unspecified number of users across 110 countries.
Broader spyware targeting in Serbia
SHARE Foundation said that at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026. The group included members of the student movement, activists, a member of parliament and a local councillor from opposition parties. The incidents coincided with local elections held on 29 March 2026.
The Pegasus case is part of a wider pattern of documented surveillance-technology abuse in the country. Earlier reporting described the use of Cellebrite forensic tools to deploy NoviSpy, an Android spyware family. In a separate 2026 incident, another student movement member’s phone was compromised with a new version of NoviSpy after the device was confiscated during police questioning.
Android cases add a second mobile risk
Amnesty International Security Lab head Donncha Ó Cearbhaill said SHARE’s forensic findings showed that Serbian students continued to be targeted with invasive Android spyware installed while they were detained by Serbian authorities. He added that the latest case revealed a newly built Android spyware tool with functionality similar to NoviSpy and specific measures intended to avoid detection by security experts.
SHARE also detected the same spyware strain on a second device after private Viber messages from that phone were disclosed live on Informer TV, a Serbian pro-government news and media television channel. The cases show that compromise can involve both remotely delivered exploits and access to a device while it is physically held.
Defensive measures for high-risk users
Citizen Lab’s finding reinforces the importance of applying mobile operating-system updates promptly, particularly for people at risk because of their work or public role. Apple recommends that high-risk iPhone users consider enabling Lockdown Mode. Android users with sensitive information or high visibility can use Google’s Advanced Protection Program.
Meta-owned WhatsApp has also introduced Strict Account Settings, which automatically applies more restrictive settings and blocks attachments and media from people outside a user’s contact list. For businesses and civil-society organisations, the practical implication is to maintain rapid update processes, identify staff who may face targeted threats and establish a clear route for reporting and investigating suspected mobile-device compromise.

