ZeroHour
Story · 1 source · 1 articlefirst updated ()

Pegasus and NoviSpy Spyware Target Serbian Activists as 29 MEPs Call for EU Accession Slowdown

highThreat actorexploited in the wildimportance 76
What's new: CyberScoop added the political dimension: 29 MEPs demanding Serbia's EU accession slowdown and cancellation of von der Leyen's visit. The Record added Amnesty International peer review, the BIA denial, 11 phones under investigation, the live-read of a victim's texts on pro-government TV, NoviSpy's physical-access/detention install method, and Cellebrite cutting ties with Serbia. Security Affairs…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Citizen Lab and SHARE Foundation confirmed a zero-click Pegasus iMessage infection on a Serbian student activist's iPhone, part of a spyware wave hitting at least 14 people ahead of March 2026 elections; 29 MEPs now demand Serbia's EU accession be slowed…

Forensic analysis by the Citizen Lab, working with the SHARE Foundation and peer-reviewed by Amnesty International, confirmed with high-confidence indicators that a member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware through a zero-click iMessage exploit that requires no user interaction and gives attackers full device access to messages, photos, microphone and camera. The infection window was December 2025 to January 2026, and the Citizen Lab believes the exploit was patched as of iOS 18.4.1, which Apple released in April 2025. The activist was among at least 14 people in Serbia — students, activists, an MP, and a local councilor — targeted with advanced spyware since December 2025, coinciding with the March 29, 2026 local elections. The SHARE Foundation documented at least 14 Apple Threat Notification recipients across Serbia's student movement, civil society, and opposition politics, and calls it the largest documented surveillance wave in Serbia's history; the Citizen Lab treats the notifications as presumptive infections and urges screening and Lockdown Mode. Per The Hacker News, Apple sent mercenary spyware threat notifications to users in 110 countries. The Record reports 11 additional alerted phones remain under forensic investigation. On the Android side, Amnesty Tech confirmed a new detection-evading NoviSpy variant in at least two cases — found on a student activist's Android phone after Serbian authorities seized it during police questioning; NoviSpy requires physical access and is typically installed after police seize phones during detention, with Serbia previously linked to Cellebrite forensic tools used to plant it (Cellebrite cut ties with Serbia after its tools were used to install NoviSpy on detainees). The Record also reports one victim's text messages were read live on a pro-government TV network. NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned; Serbia's BIA intelligence agency dismissed the findings as sensationalism, and the Serbian government did not respond to requests for comment. In the political aftermath, 29 Members of the European Parliament sent a letter on Friday (September 4, 2026, per CyberScoop) demanding that Serbia's EU accession be slowed until an investigation into its spyware use is completed, urging European Commission President Ursula von der Leyen to cancel a planned visit to Serbia, and calling the…

  • Citizen Lab, with SHARE Foundation and Amnesty International peer review, confirmed a zero-click Pegasus iMessage infection on a Serbian student activist's iPhone between December 2025 and January 2026 (high-confidence indicators).
  • The exploit was believed patched as of iOS 18.4.1, released by Apple in April 2025.
  • At least 14 Serbian individuals targeted since December 2025 — students, activists, an opposition MP, and a local councilor — coinciding with March 29, 2026 local elections.
  • SHARE documented at least 14 Apple Threat Notification recipients; Citizen Lab treats them as presumptive infections and recommends screening and Lockdown Mode; Apple sent threat notifications to users in 110 countries.
  • 11 additional alerted phones remain under forensic investigation (The Record).
  • Amnesty Tech confirmed a new detection-evading NoviSpy Android variant in at least two cases, found after Serbian authorities seized a device; NoviSpy requires physical access, typically installed during police detention; Serbia was…
  • NoviSpy evidence pointed to Serbian government authorities; Pegasus attribution was not assigned; Serbia's BIA intelligence agency dismissed the findings; the Serbian government did not respond to comment requests.
  • 29 MEPs sent a letter (September 4, 2026, per CyberScoop) demanding Serbia's EU accession be slowed pending a spyware investigation, calling on Ursula von der Leyen to cancel a planned Serbia visit and demanding rule-of-law accountability…

Coverage timeline

  1. · 13d ago
    The Hacker News· 72
    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    Citizen Lab confirms Pegasus zero-click iMessage spyware infected a Serbian student activist's iPhone amid at least 14 spyware targets in Serbia during 2026.