Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus Zero-Click Exploit Infects Serbian Student Activist’s iPhone
A member of Serbia’s student protest movement has been infected with NSO Group’s Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the SHARE Foundation. The Citizen Lab found high-confidence indicators of infection on the individual’s iPhone across December 2025 and January 2026. The research indicated that the attack utilized an iMessage zero-click exploit believed to have been patched by Apple as of iOS 18.4.1, released in April 2025.
A zero-click exploit requires no action from the recipient, allowing spyware to be delivered without the target clicking a link or opening an attachment. Such an infection would not have been visible to the target and would grant the attacker total access to the device, including notes, pictures, and encrypted messages, as well as the ability to covertly activate the microphone and camera. 📱🔒
The investigation began after the individual received an Apple Threat Notification warning of targeting with mercenary spyware. This notification was among at least 14 documented by the SHARE Foundation involving members of Serbia’s student movement and civil society, as well as an opposition member of parliament. The Citizen Lab noted that the targeting came ahead of key 2026 election cycles. This case is part of a longer history of surveillance abuses in Serbia, including previous Pegasus targeting of civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware. The SHARE Foundation and Amnesty Tech confirmed that a new version of NoviSpy had been found on another student movement member’s device.
The laboratory stated that its forensic work on the other notification cases is ongoing, adding that this confirmation demonstrates continued targeting of Serbia’s pro-democracy movement with mercenary spyware.
Recommendations for Defense
The Citizen Lab advises that an Apple Threat Notification should be treated as presuming infection, urging recipients to seek expert assistance immediately. They recommend that close contacts, such as family members and collaborators, seek spyware screening, that individuals at heightened risk enable Apple’s Lockdown Mode, and that all devices be kept updated. Individuals in Serbia are encouraged to contact the SHARE Foundation, while recipients elsewhere should reach out to trusted experts such as Access Now’s Digital Security Helpline.
For more details, Read full article!