A concerning development has emerged from the heart of Serbia’s student protest movement, as it has been reported that a member of this group has fallen victim to Pegasus spyware, a surveillance tool developed by the NSO Group. This alarming situation was revealed through a comprehensive forensic investigation conducted by the Citizen Lab, in conjunction with the SHARE Foundation. The researchers have indicated that the individual was infected via a zero-click exploit on iMessage, which is particularly insidious as it requires no action from the target.
The Citizen Lab has published detailed findings asserting that high-confidence indicators of Pegasus infection were detected on the individual’s iPhone during a period stretching from December 2025 to January 2026. It is vital to note, however, that the researchers also expressed uncertainty regarding the possibility of additional infections occurring outside this timeframe, highlighting the ongoing risks posed to individuals engaged in activism and public dissent.
In an act of cautious transparency, the target of the spyware acknowledged their situation but chose to remain unnamed for security purposes. Notably, the investigation’s findings included the critical detail of withholding the exact date of infection to further protect the individual’s privacy amid a climate of heightened surveillance and potential repercussions.
The September 2 research highlighted that the exploit utilized to gain access to the individual’s device was an iMessage zero-click exploit. According to the Citizen Lab, Apple had patched this vulnerability in iOS version 18.4.1, which was released in April 2025. This context sheds light on the urgency of maintaining updated software, as such exploits can allow malicious actors to infiltrate devices without requiring any user interaction—an alarming reality for those targeted.
The implications of such an infection extend far beyond simple data theft. The spyware grants attackers unrestricted access to the target’s device, encompassing sensitive information such as notes, photographs, and encrypted messages. Furthermore, the spyware’s capabilities include the covert activation of the microphone and camera, rendering the targeted individual vulnerable to continuous surveillance without their consent or knowledge.
In response to this breach, the Citizen Lab noted that the investigation was instigated following the receipt of an Apple Threat Notification by the affected individual. This notification was part of a broader context in which at least 14 similar notifications were documented by the SHARE Foundation. The range of targets included not only members of the student movement but also civil society actors and even an opposition member of parliament. These targeting incidents appear to align ominously with the lead-up to the significant election cycles anticipated in Serbia during 2026.
Historically, Serbia has been plagued by issues of surveillance abuse, a fact that the Toronto-based Citizen Lab emphasized in its findings. Previous incidents involving Pegasus spyware targeting civil society activists and the use of forensic tools like Cellebrite to deploy alternative spyware, such as NoviSpy, indicate a worrying trend. On the same day as the recent report, both the SHARE Foundation and Amnesty Tech confirmed the discovery of a new variant of NoviSpy on the device of another member of the student movement, amplifying concerns around the pervasive nature of such surveillance activities.
In light of these developments, a crucial message has been imparted to those who receive Apple Threat Notifications. The Citizen Lab has strongly advised that these notifications should be interpreted as indicators of potential infection, urging recipients to seek expert assistance without delay. Moreover, it has recommended that close contacts—such as family members and collaborators—should undergo spyware screening.
Individuals, especially those in positions of heightened risk, are also urged to utilize tools like Apple’s Lockdown Mode and maintain their devices with the latest security updates. In Serbia, activists are encouraged to reach out to the SHARE Foundation, while individuals located elsewhere should seek guidance from trusted organizations like Access Now’s Digital Security Helpline. Although there is no substitute for personalized advice, the availability of online resources such as the Security Planner is a beneficial tool for those navigating the dangers of digital surveillance.
As the forensic investigation into these notifications continues, the Citizen Lab reiterates the ongoing threat posed by mercenary spyware to pro-democracy movements in Serbia, underscoring the importance of vigilance and proactive measures in safeguarding personal privacy and security in an increasingly surveilled digital landscape.
