ZeroHour
Story · 1 source · 1 articlefirst updated ()

Pegasus and NoviSpy spyware hit Serbian activists; 29 MEPs urge slowing Serbia's EU accession

highThreat actorexploited in the wildimportance 76
What's new: First merged summary (no previous version). The story advanced from forensic findings in the September 3 report (zero-click Pegasus via an iMessage exploit patched in iOS 18.4.1; new NoviSpy variant on a seized Android phone; at least 14 targets since early 2026) to political consequences in the September 4 report (29 MEPs seeking a slowdown of Serbia's EU accession, rule-of-law accountability…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Citizen Lab, Amnesty International/Amnesty Tech and the SHARE Foundation documented zero-click Pegasus (iMessage exploit, patched in iOS 18.4.1) and a new NoviSpy variant on Serbian activists' phones, with at least 14 people targeted since early 2026; 29 MEPs…

The Citizen Lab, working with the SHARE Foundation, confirmed that a Serbian student protest movement member's iPhone was infected with NSO Group's Pegasus via an iMessage zero-click exploit between December 2025 and January 2026; the infection required no victim interaction and granted access to messages, photos, microphone and camera, and Apple patched the exploit in iOS 18.4.1. The SHARE Foundation has documented at least 14 targeted individuals since early 2026 — student activists, civil society figures, an opposition MP and a local councilor — coinciding with the March 2026 local elections, and calls it the largest documented surveillance wave in Serbia's history. SHARE and Amnesty Tech also found a new NoviSpy variant on a student activist's Android phone after Serbian authorities seized it during police questioning. On attribution, the reports differ in scope: NoviSpy evidence points to Serbian government authorities, while the party that deployed Pegasus was not assigned (CyberScoop), though the spyware itself is NSO Group's (Security Affairs). Following the joint report by the SHARE Foundation with Amnesty International and the Citizen Lab, 29 Members of the European Parliament sent a letter Friday (2026-09-04) demanding Serbia's EU accession be slowed until an investigation into the spyware use is completed; they urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia, demanded rule-of-law accountability conditions, and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. Targets were advised to enable Lockdown Mode and treat Apple Threat Notifications as presumed infections. The Serbian government did not respond to requests for comment.

  • Citizen Lab, with the SHARE Foundation, confirmed a Serbian student activist's iPhone was infected with NSO Group's Pegasus via a zero-click iMessage exploit between December 2025 and January 2026; no victim interaction was required, and…
  • Apple patched the iMessage exploit in iOS 18.4.1.
  • SHARE Foundation has documented at least 14 targeted individuals since early 2026, including student activists, civil society figures, an opposition MP and a local councilor, coinciding with the March 2026 local elections; SHARE calls it…
  • SHARE and Amnesty Tech found a new NoviSpy variant on a student activist's Android phone after Serbian authorities seized it during police questioning.
  • Attribution: NoviSpy evidence points to Serbian government authorities; Pegasus deployment was not assigned (CyberScoop), though the spyware is NSO Group's (Security Affairs).
  • Twenty-nine MEPs sent a letter Friday (2026-09-04) demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed; they also urged cancellation of Ursula von der Leyen's planned Serbia visit and sought…
  • Targets were advised to enable Lockdown Mode and treat Apple Threat Notifications as presumed infections.
  • The Serbian government did not respond to requests for comment.

Coverage timeline

  1. · 12d ago
    Security Affairs· 76
    Pegasus and NoviSpy Used Against Serbian Protesters

    Citizen Lab confirmed zero-click Pegasus infected a Serbian student activist's iPhone, part of the largest documented Serbian spyware wave targeting at least 14 people.