At least 14 people connected to Serbia’s student movement, civil society and opposition politics have been targeted with sophisticated spyware since late 2025, marking what researchers describe as the largest documented surveillance campaign of its kind in the country.

 

 

The investigation gained momentum in August 2026 after 12 people approached the Belgrade-based SHARE Foundation following Apple threat notifications warning that their iPhones had been targeted with mercenary spyware. Subsequent forensic work uncovered two additional cases involving NoviSpy, surveillance software previously identified in Serbia.

Those targeted include members of Serbia’s student movement and activists, as well as an opposition member of parliament and a local opposition councilor. Researchers noted that the surveillance activity overlapped with a politically sensitive period that included local elections held on March 29th.

One of the most significant findings came from an unnamed member of the student protest movement. Citizen Lab, working with SHARE Foundation, found high-confidence forensic evidence that the person’s iPhone had been infected with Pegasus between December 2025 and January 2026.

Pegasus is commercial surveillance software developed by Israel-based NSO Group. Once successfully deployed, it can provide extensive access to information stored on a smartphone, including communications, photographs, and other sensitive data. It can also enable covert access to a device’s microphone and camera.

In the Serbian case, investigators determined that the Pegasus infection involved a zero-click vulnerability in Apple’s iMessage service. Unlike conventional phishing attacks, a zero-click exploit does not require the victim to open an attachment, follow a malicious link, or approve an installation. Researchers believe the vulnerability used in the attack had been patched by Apple in iOS 18.4.1.

The investigation also identified a new version of NoviSpy on devices associated with the student movement. NoviSpy is an Android surveillance tool that had already been documented in Serbia. Previous research found cases in which it was covertly installed on activists’ phones while the devices were temporarily out of their possession during interactions with Serbian authorities.

Who authorized the latest Pegasus targeting has not been publicly established. Serbia’s Security Intelligence Agency, known as BIA, rejected allegations surrounding the surveillance reports as “purely trivial sensationalism” and said that it operates in accordance with Serbian law.

Forensic examinations of additional devices are continuing, meaning the confirmed number of targets may not represent the full scale of the surveillance activity. Researchers have described the cases documented so far as an unprecedented wave of advanced spyware targeting in Serbia.

Site Disclaimer

2-remove-virus.com is not sponsored, owned, affiliated, or linked to malware developers or distributors that are referenced in this article. The article does not promote or endorse any type of malware. We aim at providing useful information that will help computer users to detect and eliminate the unwanted malicious programs from their computers. This can be done manually by following the instructions presented in the article or automatically by implementing the suggested anti-malware tools.

The article is only meant to be used for educational purposes. If you follow the instructions given in the article, you agree to be contracted by the disclaimer. We do not guarantee that the artcile will present you with a solution that removes the malign threats completely. Malware changes constantly, which is why, in some cases, it may be difficult to clean the computer fully by using only the manual removal instructions.

Leave a Reply