Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Researchers confirmed the first 2026 Pegasus infection and a new NoviSpy variant on 14 Serbian activists, likely surveillance by Serbian authorities ahead of elections.
Citizen Lab confirmed with high probability the first forensically confirmed Pegasus infection of 2026, on a Serbian student activist hacked via a zero-click exploit between December of last year and January. Amnesty International confirmed two devices infected with a new NoviSpy variant, and the SHARE Foundation documented 14 targets including a member of parliament and a local government official, the largest documented spyware wave in Serbia to date. Evidence points to Serbian police or intelligence services, with NoviSpy infections occurring around police detention ahead of key local and parliamentary elections. Apple threat notifications preceded the findings, and updated iOS versions break the exploit chain.
- 14 targets included one member of parliament, a local official, and student activists
- NoviSpy infections followed police questioning and disclosure of private messages by a loyalist outlet
- Pegasus delivered via zero-click exploit; Apple's iOS updates break this exploit
- Largest documented spyware surveillance wave in Serbia to date, ahead of March elections
Full article864 words · extracted from cyberscoop.com · click to collapse

Skip to main content
Get our latest cybersecurity news first on Google.
Click here!
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
Listen to this article
0:00
Learn more.
This aerial photograph shows demonstrators and students as they gather in front of Serbia's Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)
Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date.
The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed the Pegasus infection of a student activist with “high probability,” while Amnesty International confirmed that two devices had been infected with a new version of the NoviSpy spyware.
The SHARE Foundation noted that the infections coincided with the build-up to key local elections in March that were viewed as a test of the ruling Serbian Progressive Party, with student protests rising in the wake of the 2024 Novi Sad railway station canopy collapse, and in advance of October parliamentary elections.
Serbian activists have found themselves targeted with spyware numerous times before, including by Pegasus and NoviSpy . But the SHARE Foundation said this was the biggest wave there so far.
Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.
NoviSpy variant infections
One NoviSpy variant infection came after authorities took a student’s phone during police questioning, and the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party, SHARE Foundation said.
The SHARE Foundation said signs point to Serbian police or secret service being behind the NoviSpy variant cases, with Amnesty International offering a similar assessment.
“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop. “As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities.”
Pegasus infection
In the case of the infection from NSO Group’s Pegasus spyware, it’s rare for investigators to determine who specifically made use of it, although they found that the student’s device was hacked with a Pegasus zero-click exploit from December of last year to January of this year. The infection came via a zero-click exploit — meaning without victim interaction.
But Citizen Lab said the Serbian case harkens back to the first discovery of Pegasus a decade ago when it was against a pro-democracy activist, Ahmed Mansoor.
“Today, Pegasus is still being used to hack people campaigning for democracy,” said John Scott-Railton, senior researcher. “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”
NSO Group maintains that its spyware is for usage against terrorism and crime, and that it halts any abuses it discovers.
The spyware discoveries in Serbia came after Apple sent threat notifications to the targets.
“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” said Bill Marczak, senior researcher at Citizen Lab.
Latest Podcasts
Government
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Dogged Russia-based botnet dismantled after 23-year run
Technology
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
Bipartisan Senate bill aims to prepare energy sector for Q-Day
Threats
FBI raises alarm over deceptive phishing campaign targeting prominent people
McKesson copes with fallout from data theft extortion attack
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
ATF confirms cyberattack hit system containing info on its investigation targets
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Postal Service moves to finalize mail ballot regs before SCOTUS ruling
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/