The Citizen Lab confirmed a Pegasus spyware infection on the iPhone of a Serbian student activist on September 2, 2026. The attack used a zero-click iMessage exploit, so it needed no clicks or taps. It forms part of the largest documented spyware wave in Serbia’s history. At least 14 people were targeted ahead of key 2026 elections.
At a glance
| Malware family | Pegasus (plus a new NoviSpy Android variant) |
| Operator | Not publicly established; Pegasus sold only to states |
| Targets | Serbian students, activists, an MP, a local councilor |
| Delivery vector | Zero-click iMessage exploit (Pegasus); physical access (NoviSpy) |
| Key capabilities | Full device access, mic and camera activation |
| Source | The Citizen Lab and the SHARE Foundation |
TL;DR
Researchers confirmed a Pegasus spyware infection on a Serbian student’s phone. The zero-click iMessage exploit required no user action. The case anchors a wider wave of at least 14 spyware targets before Serbia’s 2026 elections.
What happened
The Citizen Lab and the SHARE Foundation analyzed the device after an Apple Threat Notification. The alert warns users of likely mercenary spyware targeting. Forensics then confirmed the Pegasus spyware, built by Israel’s NSO Group. Researchers found high-confidence infection indicators across December 2025 and January 2026.
The victim consented to publication but asked to stay unnamed. Researchers also withheld the exact infection date to protect their privacy.
How the attack works
Pegasus reached the phone through a zero-click iMessage exploit. As the Citizen Lab explains, such an infection “would not have been visible to the target.” No link, tap, or download was required. The Citizen Lab believes Apple patched this exploit as of iOS 18.4.1, released in April 2025.
The impact is total. Citizen Lab notes Pegasus “allows an attacker to do anything that a user can do.” It can read notes, photos, and even encrypted messages. It can also covertly switch on the microphone and camera.
A second spyware in the wave
SHARE and Amnesty International’s Security Lab confirmed two infections with a new NoviSpy version. NoviSpy is Android spyware first found in Serbia in 2024. Unlike Pegasus, it needs physical access to install. In one case, a student’s phone had been confiscated during police questioning. Amnesty says the new build was “newly built with specific efforts taken to avoid detection.”
Who is behind it
Attribution needs care here. Forensics confirm the tool: Pegasus is NSO Group’s product, sold only to states. However, the findings do not publicly establish who ordered or ran this specific attack. Serbia has a documented history of spyware abuse, including earlier Pegasus targeting and NoviSpy planted via Cellebrite tools. Prior NoviSpy traffic was traced to a server tied to Serbia’s security agency. Even so, the operator of this 2026 Pegasus case remains officially unconfirmed.
The pattern still matters for readers. Pegasus is military-grade spyware, and its control servers usually sit inside the client state’s own premises. NSO has also faced legal pressure abroad, including a large court judgment over past WhatsApp-based Pegasus abuse. Independent labs stress that confirming the tool is not the same as naming the customer. So this report documents targeting and infection, not a proven chain of command.
Scale and victims
The numbers come from SHARE and the Citizen Lab. SHARE documented at least 14 targets since early 2026. One Pegasus infection is forensically confirmed. Two more are confirmed NoviSpy cases. The remaining 11 received Apple Threat Notifications and are treated as presumed infected. Targets include student activists, an opposition MP, and a local councilor.
The timing raises the stakes. The targeting lines up with local elections held on March 29, 2026, and further parliamentary elections ahead. As Citizen Lab warns, Serbia’s “peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles.”
The human cost reaches beyond the phones. SHARE notes that spyware exposes everyone whose data sits on a targeted device, not just the owner. In one case, private Viber messages from a targeted phone were aired live on a Serbian TV channel. Surveillance of students, an MP, and a councilor also strikes at fair political competition. That chilling effect can quietly suppress speech, organizing, and dissent.
Defense and detection guidance
Treat an Apple Threat Notification as serious. The Citizen Lab advises recipients to assume infection and seek expert help at once. In Serbia, affected users should contact the SHARE Foundation. Elsewhere, groups like Access Now’s Digital Security Helpline support at-risk civil society.
At-risk users should also harden their devices. Apple provides step-by-step instructions on how to keep your iPhone updated to recent releases. High-risk users should enable Lockdown Mode, which sharply reduces the attack surface. Android users can turn on Advanced Protection. Above all, keep every device fully updated.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!