Pegasus Spyware Found on Serbian Student Activist’s iPhone in Zero-Click Attack

Nancy Tyson  - Tech Writer
Last updated: September 3, 2026
Human Written
Share
Pegasus Spyware Found on Serbian Student Activist's iPhone in Zero-Click Attack
Radar Rundown
  • The Citizen Lab, working with Serbia’s SHARE Foundation, confirmed that Pegasus spyware infected the iPhone of a member of Serbia’s student protest movement.

  • The attack used a zero-click exploit through iMessage, meaning the target did not need to tap or open anything for the infection to happen.

  • At least 14 people in Serbia have faced advanced spyware attacks since early 2026, including activists, a lawmaker, and opposition party members.

A powerful and invisible spyware tool infected the iPhone of a Serbian student activist. The Citizen Lab, together with Serbia’s SHARE Foundation, made the discovery public. The spyware used was Pegasus, a tool built by the Israeli company NSO Group.

The attack did not need the victim to click any link or open any file. It went straight in through Apple’s iMessage app without the target knowing. Experts call this kind of attack a “zero-click exploit,” and it is one of the hardest types to detect or stop.

According to the Citizen Lab, the analysis confirmed that a zero-click iMessage exploit delivered NSO Group’s Pegasus spyware onto the device. Strong signs of infection appeared across a period spanning December 2025 through January 2026. However, the Citizen Lab noted that earlier infections before that window cannot be ruled out.

Apple has since fixed the flaw. The company released iOS 18.4.1 in April 2025, and that update addressed the exact weakness the attackers used.

Serbia’s student movement caught in the crosshairs

The discovery did not come out of nowhere. Apple had already sent out a fresh round of threat alerts to users it suspected had been targeted by mercenary spyware. The company sent those alerts to an unspecified number of users spread across 110 countries.

The SHARE Foundation confirmed that at least 14 people in Serbia have faced targeting with advanced spyware tools since the start of 2026. The targets were not random. They included members of the student protest movement, activists, a member of parliament, and local councillors from opposition parties.

The timing also raised red flags. Many of the incidents happened right around Serbia’s local elections on March 29, 2026. That timing suggests the spyware may have had a political motive.

One student movement member’s phone was compromised in a different way. Authorities confiscated the device during police questioning. After that, a newer version of a spyware tool called NoviSpy showed up on the phone. NoviSpy targets Android devices rather than iPhones.

According to Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, Serbian students continue to face targeting with invasive Android spyware tools. He said the tools get installed on their devices while authorities hold them in detention.

Ó Cearbhaill also noted that the 2026 case uncovered a new Android spyware strain. It works similarly to NoviSpy, but builders put extra effort into making it harder for security researchers to spot.

Private messages aired on TV, second device confirmed infected

The SHARE Foundation also linked the same spyware strain to a second device. In that case, private Viber messages from a victim’s phone were broadcast live on Informer TV, a Serbian television channel known for supporting the government. The broadcast of private messages confirmed that someone had access to that phone’s contents.

This incident is part of a wider and growing list of documented surveillance abuses in Serbia. Earlier cases showed authorities using Cellebrite forensic tools to install NoviSpy on phones taken during police stops or questioning. The pattern points to a coordinated effort to monitor people involved in opposition politics and civil activism in the country.

How to stay protected

People who face higher risk because of their work or public profile can take practical steps right now. Keeping phones updated with the latest software is the most important move. For iPhone users, Apple’s Lockdown Mode adds a strong layer of defense against advanced attacks like Pegasus.

Google offers a similar tool for Android users. It is called the Advanced Protection Program, and it locks down accounts for people who handle sensitive information or carry a high public profile.

WhatsApp, owned by Meta, also rolled out a feature called Strict Account Settings earlier this year. The feature automatically sets the most restrictive privacy options on a user’s account. It also blocks attachments and media from anyone not already saved in the user’s contacts. This makes it harder for attackers to sneak malicious files through the app.

Spyware like Pegasus does not target ordinary users at random. But for journalists, activists, lawyers, and anyone working close to political movements, the threat is real and growing.

Google’s AI is under fire: a class-action lawsuit claims Gemini secretly scanned Gmail, Chat, and Meet messages without consent. Users had to dig through hidden menus to opt out. Even experts got confused. Privacy? What privacy?

Share this article

About the Author

Nancy Tyson

Nancy Tyson

Tech Writer

Nancy has been working as a Cybersecurity writer for over three years and contributes her expertise in the VPN area. Due to the technology element in Nancy’s education, she has acquired the ability to assess the online security environment objectively and explain concepts in simple terms to the readers of articles in the field. Besides using her time to learn about new VPN services, Nancy likes cooking, reading a good book, and often going to parties.

More from Nancy Tyson

Comments

No comments.