← Back to Feed

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

September 3, 2026 · The Hacker News · Severity: HIGH

The iPhone of a Serbian student protest member was infected with NSO Group's Pegasus spyware via a zero-click iMessage exploit, according to Citizen Lab and the SHARE Foundation. The infection occurred between December 2025 and January 2026, though additional infections may have occurred, and Apple addressed the vulnerability in iOS 18.4.1. At least 14 people in Serbia, including activists, a parliament member, and opposition councilors, have been targeted with advanced spyware since early 2026, coinciding with local elections. Another student’s phone was compromised with a new Android spyware similar to NoviSpy after being confiscated during police questioning, with evidence of the spyware being used to leak private messages to pro-government media.

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware , according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said . "We found high-confidence indicators of infection from a period across December 2025 January 2026; however, this does not preclude the possibility of additional infections." It's assessed that the zero-click exploit used in the attack targeted Apple iMessage, and has been addressed by Apple with iOS 18.4.1 , which was released in April 2025. The discovery comes in the aftermath of Apple sending a new set of threat notifications to customers whom it suspected may have been targeted by mercenary spyware attacks. The alerts were sent to an unspecified number of users in 110 countries. In all, at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026, the SHARE Foundation confirmed . Among those targeted were student movement members, activists, a member of parliament, and a local councilor from opposition parties. The timing of these incidents coincided with the local elections held on March 29, 2026. Another student movement member had their phone compromised with a new version of the NoviSpy Android spyware after their device was confiscated during police questioning. "The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities," Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, said. "The latest 2026 case also reveals a new Android spyware, similar in functionality to NoviSpy, but newly built with specific efforts taken to avoid detection by security experts." SHARE said the same spyware strain has been detected on a second device, after private Viber messages from that phone were disclosed live on Informer TV, a Serbian pro-government news and media television channel.  The development is the latest in a string of documented abuses of surveillance technology in the country, including the use of Cellebrite forensic tools to deploy NoviSpy. Users who are at risk because of who they are and what they do should keep the devices up-to-date and consider enabling Lockdown Mode on iOS. Google also offers an Advanced Protection Program to safeguard Android users with high visibility and sensitive information from targeted online attacks. Earlier this year, Meta-owned WhatsApp announced a feature called Strict Account Settings to protect users against advanced cyber attacks by automatically locking certain settings to the most restrictive options, while blocking attachments and media from people not in a user's contact list. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • An iMessage zero-click exploit infected a Serbian student activist's iPhone with NSO Group's Pegasus spyware.
  • Citizen Lab confirmed infection indicators from December 2025 to January 2026, with possible additional infections.
  • The discovery results from collaboration between Citizen Lab and Serbia's SHARE Foundation investigating the attack.
☕ Buy a Coffee