Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
Citizen Lab confirmed a zero-click iMessage exploit was used to infect an iPhone with NSO Group's Pegasus spyware, targeting a member of Serbia's student protest movement between December 2025 and January 2026 At least 14 people in Serbia, including activists, a parliament member, and a local councilor, have been targeted with advanced spyware since the start of 2026, coinciding with local elections on March 29, 2026 A new Android spyware variant, similar to NoviSpy but designed to evade detecti
Analysis
TL;DR
- Citizen Lab confirmed a zero-click iMessage exploit was used to infect an iPhone with NSO Group's Pegasus spyware, targeting a member of Serbia's student protest movement between December 2025 and January 2026
- At least 14 people in Serbia, including activists, a parliament member, and a local councilor, have been targeted with advanced spyware since the start of 2026, coinciding with local elections on March 29, 2026
- A new Android spyware variant, similar to NoviSpy but designed to evade detection, was discovered installed on devices during police confiscation and questioning
- Apple addressed the iMessage zero-click vulnerability in iOS 18.4.1 (released April 2025), while the same spyware strain was found on a second device after private Viber messages were publicly disclosed on a pro-government TV channel
- The attacks represent a broader pattern of surveillance technology abuse in Serbia, including the use of Cellebrite forensic tools, prompting recommendations for Lockdown Mode, iOS updates, and Google's Advanced Protection Program
Why It Matters
This case illustrates the escalating weaponization of commercial spyware against civil society and political opposition in authoritarian-leaning contexts, demonstrating how zero-click exploits can bypass even hardened mobile platforms without any user interaction. The coordination between state actors and mercenary surveillance providers like NSO Group, combined with physical device confiscation for Android infections, highlights the multi-vector nature of modern digital repression that practitioners must account for in threat modeling and security assessments.
Technical Details
- The Pegasus infection utilized a zero-click iMessage exploit, meaning the target device was compromised without any action required from the user, a hallmark of NSO Group's most advanced capabilities
- Apple patched the exploited vulnerability in iOS 18.4.1, released in April 2025, indicating the attack leveraged a previously known and remediated flaw
- A new Android spyware strain, functionally similar to NoviSpy but engineered with anti-detection measures, was physically installed on devices during police detention using Cellebrite forensic tools
- The second infected device was identified after private Viber communications were extracted and broadcast live on Informer TV, a pro-government media outlet, suggesting intelligence-driven public shaming as a secondary attack objective
- Amnesty International's Security Lab and the SHARE Foundation conducted forensic analysis confirming the infections, with high-confidence indicators spanning December 2025 to January 2026
Industry Insight
- Organizations supporting at-risk journalists, activists, and opposition figures should prioritize enabling platform-specific hardening features such as Apple's Lockdown Mode and Google's Advanced Protection Program, while ensuring devices remain updated past known patched vulnerabilities
- The convergence of remote zero-click exploits and physical device seizure for spyware deployment demands a dual-layer security strategy that addresses both network-based and physical-access threat vectors in risk assessments
- The public disclosure of private communications via state-aligned media represents an emerging hybrid tactic combining technical surveillance with psychological operations, suggesting that threat intelligence programs should monitor not only technical indicators of compromise but also patterns of information manipulation correlated with device infections
Disclaimer: The above content is generated by AI and is for reference only.