AI Security AI安全 7h ago Updated 2h ago 更新于 2小时前 45

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone 佩加索斯零点击间谍软件漏洞感染塞尔维亚学生运动成员iPhone

Citizen Lab confirmed a zero-click iMessage exploit was used to infect an iPhone with NSO Group's Pegasus spyware, targeting a member of Serbia's student protest movement between December 2025 and January 2026 At least 14 people in Serbia, including activists, a parliament member, and a local councilor, have been targeted with advanced spyware since the start of 2026, coinciding with local elections on March 29, 2026 A new Android spyware variant, similar to NoviSpy but designed to evade detecti NSO Group的Pegasus间谍软件通过iMessage零点击漏洞感染塞尔维亚学生运动成员iPhone,攻击时间窗口为2025年12月至2026年1月 Apple已通过iOS 18.4.1修复该漏洞,但同期至少14名塞尔维亚人(含学生、活动家、议员)遭高级间谍软件针对 新型Android间谍软件(类似NoviSpy)被用于警方扣押期间感染设备,专门设计以规避安全专家检测 Citizen Lab与SHARE Foundation联合取证确认感染指标,揭示监控技术被用于压制政治异议的模式 安全厂商正推出防护功能(如iOS锁定模式、WhatsApp严格设置、Google高级保护计划)应对零点击

65
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Citizen Lab confirmed a zero-click iMessage exploit was used to infect an iPhone with NSO Group's Pegasus spyware, targeting a member of Serbia's student protest movement between December 2025 and January 2026
  • At least 14 people in Serbia, including activists, a parliament member, and a local councilor, have been targeted with advanced spyware since the start of 2026, coinciding with local elections on March 29, 2026
  • A new Android spyware variant, similar to NoviSpy but designed to evade detection, was discovered installed on devices during police confiscation and questioning
  • Apple addressed the iMessage zero-click vulnerability in iOS 18.4.1 (released April 2025), while the same spyware strain was found on a second device after private Viber messages were publicly disclosed on a pro-government TV channel
  • The attacks represent a broader pattern of surveillance technology abuse in Serbia, including the use of Cellebrite forensic tools, prompting recommendations for Lockdown Mode, iOS updates, and Google's Advanced Protection Program

Why It Matters

This case illustrates the escalating weaponization of commercial spyware against civil society and political opposition in authoritarian-leaning contexts, demonstrating how zero-click exploits can bypass even hardened mobile platforms without any user interaction. The coordination between state actors and mercenary surveillance providers like NSO Group, combined with physical device confiscation for Android infections, highlights the multi-vector nature of modern digital repression that practitioners must account for in threat modeling and security assessments.

Technical Details

  • The Pegasus infection utilized a zero-click iMessage exploit, meaning the target device was compromised without any action required from the user, a hallmark of NSO Group's most advanced capabilities
  • Apple patched the exploited vulnerability in iOS 18.4.1, released in April 2025, indicating the attack leveraged a previously known and remediated flaw
  • A new Android spyware strain, functionally similar to NoviSpy but engineered with anti-detection measures, was physically installed on devices during police detention using Cellebrite forensic tools
  • The second infected device was identified after private Viber communications were extracted and broadcast live on Informer TV, a pro-government media outlet, suggesting intelligence-driven public shaming as a secondary attack objective
  • Amnesty International's Security Lab and the SHARE Foundation conducted forensic analysis confirming the infections, with high-confidence indicators spanning December 2025 to January 2026

Industry Insight

  • Organizations supporting at-risk journalists, activists, and opposition figures should prioritize enabling platform-specific hardening features such as Apple's Lockdown Mode and Google's Advanced Protection Program, while ensuring devices remain updated past known patched vulnerabilities
  • The convergence of remote zero-click exploits and physical device seizure for spyware deployment demands a dual-layer security strategy that addresses both network-based and physical-access threat vectors in risk assessments
  • The public disclosure of private communications via state-aligned media represents an emerging hybrid tactic combining technical surveillance with psychological operations, suggesting that threat intelligence programs should monitor not only technical indicators of compromise but also patterns of information manipulation correlated with device infections

TL;DR

  • NSO Group的Pegasus间谍软件通过iMessage零点击漏洞感染塞尔维亚学生运动成员iPhone,攻击时间窗口为2025年12月至2026年1月
  • Apple已通过iOS 18.4.1修复该漏洞,但同期至少14名塞尔维亚人(含学生、活动家、议员)遭高级间谍软件针对
  • 新型Android间谍软件(类似NoviSpy)被用于警方扣押期间感染设备,专门设计以规避安全专家检测
  • Citizen Lab与SHARE Foundation联合取证确认感染指标,揭示监控技术被用于压制政治异议的模式
  • 安全厂商正推出防护功能(如iOS锁定模式、WhatsApp严格设置、Google高级保护计划)应对零点击攻击

为什么值得看

本文揭示了零点击漏洞在政治监控中的实战应用,展示了间谍软件技术向规避检测方向的演进,对关注恶意软件防御、漏洞响应及数字权利安全的AI从业者具有直接参考价值。安全厂商的防护功能迭代(如自动锁定设置、附件过滤)为高风险用户提供了可落地的缓解策略,同时凸显了取证分析在追踪国家支持型网络攻击中的关键作用。

技术解析

  • 零点击漏洞利用链:Pegasus通过iMessage协议发送恶意载荷,无需用户交互即可实现设备感染,攻击时间窗口集中在2025年12月至2026年1月,表明攻击者可能利用未公开漏洞进行精准投放。
  • 漏洞修复与时间线:Apple在2025年4月发布的iOS 18.4.1中已修复该iMessage漏洞,但感染事件仍发生在修复后,暗示攻击者可能持有多个零日漏洞或采用延迟利用策略。
  • 新型Android间谍软件特征:SHARE Foundation发现一款类似NoviSpy的新Android间谍软件,其架构专门优化以规避安全专家检测,且通过警方扣押设备期间物理安装,体现“扣押-感染”攻击模式。
  • 取证分析方法:Citizen Lab与SHARE Foundation采用联合取证流程,通过高置信度指标(如内存残留、网络通信特征)确认感染,并为后续类似调查提供方法论参考。
  • 攻击目标分布:2026年以来至少14名塞尔维亚人遭针对,包括学生运动成员、活动家、反对党议员及地方议员,目标选择与2026年3月29日地方选举时间高度吻合。

行业启示

  • 监控技术政治化趋势加剧:零点击漏洞和规避检测的间谍软件正被用于压制政治异议,尤其在选举期间,AI从业者需关注恶意软件检测技术如何应对此类定向攻击。
  • 安全响应需分层推进:厂商应加速漏洞修复(如iOS 18.4.1的及时发布),同时推广防护功能(如锁定模式、严格账户设置),高风险用户需保持设备更新并启用高级保护计划。
  • 取证与协作成为关键能力:联合调查机构(如Citizen Lab)的取证方法为追踪国家支持型网络攻击提供范本,组织应投资持续监控和跨机构协作机制以应对复杂间谍软件威胁。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究