Forensic investigators at the University of Toronto’s Citizen Lab and Amnesty International confirmed on September 2 that Serbia deployed NSO Group’s Pegasus military-grade spyware against its own pro-democracy student movement using an iMessage zero-click exploit — an attack that required no action whatsoever from the target, and that Apple has since patched in iOS 18.4.1. The same day, the Serbian government’s Security Information Agency (BIA) dismissed the forensic findings as “trivial sensationalism,” and President Aleksandar Vučić called the evidence “suspicions without a single piece of evidence.”
The infections documented by the Belgrade-based SHARE Foundation — confirmed independently by Citizen Lab and Amnesty International — are the largest documented wave of mercenary spyware surveillance in Serbia’s history, according to the groups, targeting at least 14 people in the student protest movement, civil society, and the political opposition ahead of October 2026 parliamentary elections. If you own an iPhone that has not been updated to iOS 18.4.1, update it now: Citizen Lab senior researcher Bill Marczak stated that the zero-click exploit used in this case has been rendered ineffective by Apple’s patch.
How Pegasus Got In Without Clicking Anything
Pegasus is military-grade spyware sold exclusively to vetted government and state agencies by the Israeli company NSO Group. Once installed, it grants total access to a device — messages, photos, contacts, app data, and the ability to covertly activate the microphone and camera — all without leaving any visible trace. The key technical finding in the Serbia case is the delivery mechanism: an iMessage zero-click exploit used to infect the device.
A zero-click exploit works by targeting vulnerabilities in how a device processes incoming data automatically — in this case, how Apple’s iMessage handles certain content without user interaction. The attacker sends a specially crafted message; the device’s parsing code handles it silently in the background; Pegasus is installed before the recipient sees anything. No link click, no download prompt, no notification. Citizen Lab’s analysis of forensic artifacts recovered from the infected iPhone confirmed high-confidence indicators of infection across a window spanning December 2025 through January 2026.
This is the most powerful and hardest-to-detect attack class in the commercial spyware market. NSO Group has used iMessage as a zero-click delivery vector since at least 2019, and has developed successive exploit chains — including the FORCEDENTRY exploit documented by Google’s Project Zero in 2021, which exploited Apple’s image rendering library. The 2026 Serbia exploit represents a new chain that Citizen Lab has not publicly named in full (to avoid enabling exploitation of still-unpatched devices), but which Apple closed in iOS 18.4.1.
“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” Marczak said.
What Apple’s Own System Missed — and Why That Matters
Apple sent mercenary spyware threat notifications to users in 110 countries on August 13, 2026. Twelve people in Serbia received those warnings and brought their devices to SHARE’s digital forensics team. What SHARE’s investigation then confirmed is critical: the team discovered two additional infections that Apple’s automated notification system had not flagged.
Apple’s Threat Notification system is a meaningful protective measure — it sends high-confidence alerts when it detects infrastructure or indicators associated with known mercenary spyware. But it is not comprehensive. If an attacker uses novel infrastructure, modified tools, or evasion techniques, the system can miss infections. SHARE’s work in Serbia confirmed that two of the 14 documented cases — both involving a new variant of Android spyware called NoviSpy — would have gone entirely undetected had the organization not conducted independent device forensics.
This is not a theoretical gap. In Serbia’s case, it was the physical custody attack vector that Apple’s system was structurally unable to catch: NoviSpy does not arriveted by police or intelligence agents during questioning. No iMessage required. No network indicator. Just a Cellebrite forensic extraction tool to unlock the device and a direct installation
Android Spyware Installed During Police Custody
Alongside the Pegasus finding, Amnesty International’s Security Lab separately confirmed the presence of a new, rebuilt version of NoviSpy — an Android spyware platform that prior Amnesty investigations attributed with high confidence to the BIA — on two additional devices.
In one documented case, the student activist’s phone was confiscated during police questioning; forensic evidence suggests the spyware was installed while the device was in state custody. The NoviSpy variant can access messages, photos, contacts, app data, and files — and can covertly activate the microphone and camera. Critically, Amnesty researchers found the 2026 variant had been rebuilt from the ground up with specific measures to evade detection by security experts. This represents an active technical evolution: when prior Amnesty reporting publicly documented NoviSpy’s architecture in December 2024, the BIA’s developers responded by rebuilding it.
What makes the second NoviSpy finding particularly significant is what happened after the phone was returned: private Viber messages from that device were subsequently read aloud on Informer, the Serbian state-aligned television channel. This is not just evidence of surveillance — it is evidence that the spyware had already been weaponized for active information operations. Stolen messages, broadcast publicly. This is the pattern that Polish investigators documented when they established that opposition campaign manager Krzysztof Brejza’s Pegasus-extracted texts were fed to state media TVP and used in a smear campaign ahead of the 2019 elections. Serbia is now following the same template, before the October elections.
Serbia’s Denials and What the Forensics Actually Show
The BIA called the findings “trivial sensationalism” and said it “operates exclusively in accordance with the laws of the Republic of Serbia.” President Vučić dismissed the forensic case as unsubstantiated, invoked his own wiretapping as an opposition figure, and suggested the students had expressed “suspicions without a single piece of evidence.” Parliament Speaker Ana Brnabić told Euronews Serbia the state was not behind the alleged surveillance and questioned the evidence presented.
One official, quoted by gblock.app, argued it would be “idiotic” for the state to deploy million-euro software that leaves forensic traces.
That argument does not engage with what the forensic traces actually show. In prior NoviSpy cases documented by Amnesty International in December 2024, spyware samples were configured to send stolen data to IP addresses registered to BIA servers. In at least two of those prior cases, Cellebrite UFED forensic tools were used to exploit a zero-day vulnerability in Qualcomm chipsets — affecting millions of Android devices — to gain privileged access to activists’ phones during police custody. Google’s Project Zero and Threat Analysis Group identified and patched the Qualcomm vulnerability after Amnesty reported it.
Ana Toskic Cvetinovic of the Partneri Srbija rights watchdog stated the legal position plainly: “The Criminal Procedure Code envisions the situations in which secret surveillance is allowed — there must be a reasoned court decision. To our knowledge, there is no such thing here.” Use of such software without court authorization constitutes a criminal offense under Serbian law.
Is Your iPhone at Risk?
The short answer: if you are running iOS 18.4.1 or later, the specific zero-click iMessage exploit used against the Serbian student activist has been patched. Apple addressed it as part of the iOS 18.4.1 security update.
The longer answer is more unsettling. NSO Group has maintained multiple exploit chains for iMessage since at least 2019, and historically has developed replacements after each chain is patched. The FORCEDENTRY exploit used from at least February 2021 was patched in September 2021; the BlastPass exploit documented in September 2023 was patched in iOS 16.6.1; the 2026 Serbia exploit is now patched in iOS 18.4.1. Each time a chain is patched, NSO Group has returned with another.
What this means for high-risk individuals — journalists, activists, opposition politicians, anyone who might be a target of state-level surveillance — is that keeping iOS updated is necessary but not sufficient. Citizen Lab and SHARE Foundation explicitly recommend enabling Lockdown Mode on iOS. Lockdown Mode restricts certain iMessage functionalities and other attack surfaces that Pegasus has historically exploited, significantly raising the cost of a zero-click attack. For Android users in high-risk categories, the SHARE Foundation recommends enabling Android’s Advanced Protection mode.
A Pattern Three Campaigns Deep
The September 2026 wave is not Serbia’s first. It is the third documented mercenary spyware campaign against its own civil society in under three years.
In August 2023, the Citizen Lab and Access Now confirmed spyware attack attempts on two unnamed Serbian civil society members via Apple’s HomeKit vulnerability — consistent with NSO Group’s Pegasus tactics, though the specific spyware could not be confirmed. In March 2025, Amnesty International documented two BIRN investigative journalists targeted with Pegasus via malicious links delivered through Viber; one link directed to a fake version of the N1 news website, a social engineering tactic that prior Serbian Pegasus attacks also used.
The December 2024 “Digital Prison” report by Amnesty International established that the Serbian police and BIA had, from at least 2024, been using Cellebrite UFED forensic tools to unlock activists’ phones during detention and install NoviSpy covertly — in some cases exploiting a Qualcomm zero-day to break into devices. Among the named victims: investigative journalist Slaviša Milanov, detained in February 2024, whose Samsung device was infected with NoviSpy during a police custody period; environmental activist Ivan Milosavljević Buki; and at least nine activists detained during anti-lithium-mining protests in the second half of 2024.
Cellebrite, the Israeli company whose forensic tools were used to enable those 2024 NoviSpy infections, halted sales to Serbia following publication of those findings. The 2026 wave shows that cutoff did not stop Serbia’s surveillance apparatus — it adapted. The new NoviSpy variant was rebuilt. Pegasus access continued.
This is a decade-long accumulation. The Citizen Lab has documented Serbia’s BIA as a customer of FinFisher (2014), Circles geolocation technology (2020), Cytrox/Predator (2021), and Pegasus (from at least December 2021). Faced with each vendor cutting off access or each exploit chain being patched, Serbia’s surveillance apparatus has found alternatives.
Spyware as Election Infrastructure
The timing of each documented wave has not been coincidental. The Citizen Lab has confirmed that the Pegasus infection of the student activist coincided with a campaign window spanning December 2025 through January 2026 — in the months before Serbia’s March 29, 2026 local elections, which were viewed as the first major test of the ruling Serbian Progressive Party against a student movement that emerged from the November 2024 Novi Sad railway station collapse that killed 16 people. Parliamentary elections are now scheduled for October 2026.
Andrijana Ristic, a policy adviser at the SHARE Foundation, described what is at stake: “It’s a very sensitive political time in Serbia, and there is a real chance the student movement and the opposition will be able to win the elections in October. But you cannot have a level playing field in the elections if one side is illegally obtaining information on the other.”
Opposition MP Radomir Lazović, co-president of the Green-Left Front and one of the 14 named targets, said the surveillance environment made meaningful opposition work structurally difficult: “If they are controlling us, if they’re monitoring us, and they’re tapping our phones and so on, it’s really hard to have any kind of meaningful opposition working in Serbia.”
Student activist Jelena Kontić, whose iPhone was confirmed infected with Pegasus, said at a September 3 press conference that the consequences extended beyond her own device: “Not only my privacy and security were violated, but also the privacy and security of all the people with whom I communicated at the time — citizens, students, and my family.”
The private Viber messages from the second NoviSpy-infected phone that were broadcast on Informer TV represent the clearest evidence that surveillance has already been converted into an active electoral tool. John Scott-Railton, senior researcher at the Citizen Lab, framed the broader context: “Today, Pegasus is still being used to hack people campaigning for democracy. NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”
The EU Dimension
Serbia is an EU accession candidate, and the September 2026 forensic findings arrive at a moment when Brussels faces specific pressure to act. Amnesty International’s EU 2026 Enlargement Package submission raised Serbia’s spyware use directly. The European Parliament, in a 2025 resolution, expressed “significant alarm” over Serbia’s use of spyware and surveillance against civil society and journalists, framing it as a condition of EU membership.
That spyware use is now, by forensic confirmation, continuing — and expanding in technical sophistication — after the EU expressed alarm. The 2026 wave’s documentation gives the European Commission grounds to treat ongoing surveillance against the pro-democracy movement not as a past failing but as a current disqualifying condition. Whether Brussels acts on those grounds remains to be seen.
What President Vučić Champions in Public
There is a contrast the international technology community should register. In February 2026, President Vučić attended the India AI Impact Summit in New Delhi alongside Indian Prime Minister Narendra Modi, French President Emmanuel Macron, and Brazilian President Luiz Inácio Lula da Silva, where he presented Serbia as a country that “invested significantly in digital infrastructure, data centers and supercomputers” and is “developing its own sovereign AI models.” In June 2026, he met with Chinese AI expert Kai-Fu Lee in Belgrade to discuss how AI could be used to modernize the Serbian government and improve institutional efficiency.
The government he leads simultaneously stands accused — on the basis of peer-reviewed forensic evidence from two of the world’s leading digital security research institutions — of running the largest documented mercenary spyware operation in Serbian history against its own citizens.
This is not an irony that exists only in the abstract. The same digital infrastructure buildout Vučić champions in international forums — biometric document systems, data centers, AI applications for public services — creates the data environment in which a surveillance state operates most effectively.
How to Protect Yourself
If you are a journalist, civil society worker, activist, opposition politician, or anyone who may be a target of state-level surveillance — in Serbia or anywhere — Citizen Lab and SHARE Foundation recommend the following steps:
Updating iOS to 18.4.1 or later closes the specific iMessage zero-click exploit used in the 2026 Serbia Pegasus case. Enabling Lockdown Mode on iOS substantially restricts the attack surface that Pegasus has historically exploited, at the cost of some functionality. Enabling Advanced Protection on Android limits exposure on Android devices.
If you received an Apple Threat Notification, treat it as a high-confidence indicator that your device was targeted and immediately seek expert assistance. Individuals in Serbia should contact the SHARE Foundation. People in other countries should contact Access Now’s Digital Security Helpline, which supports journalists, human rights defenders, and dissidents.
If you have not received a notification but are in a high-risk category, do not assume your device is clean. The Serbia case confirmed that Apple’s automated system missed two infections. Expert forensic screening from a trusted digital security organization is the only way to know.
Frequently Asked Questions
What is a zero-click exploit, and why can’t I protect myself by not clicking suspicious links?
A zero-click exploit installs spyware on your device without requiring any interaction from you — no link click, no download, no notification. It works by exploiting vulnerabilities in how your device automatically processes incoming data, such as the way iMessage handles certain message formats before you ever open them. In the Serbia case, an iMessage zero-click exploit was used to install Pegasus between December 2025 and January 2026. Apple closed that specific exploit in iOS 18.4.1. The practical implication: simply being careful about which links you click is not a sufficient defense against this class of attack. Keeping your operating system fully updated and enabling security features like iOS Lockdown Mode are the most meaningful protections available to consumers.
How can I tell if Pegasus is on my iPhone right now?
Consumer-level detection of Pegasus is genuinely difficult, which is precisely what makes the spyware so dangerous. Apple’s Threat Notification system provides high-confidence alerts when it detects indicators associated with known mercenary spyware infrastructure — but the Serbia case confirmed that it missed two infections. The Mobile Verification Toolkit (MVT), an open-source utility released by Amnesty International, can analyze backup files from an iPhone or Android device for traces of Pegasus. For individuals in high-risk categories — journalists, activists, opposition politicians — a forensic screening from a trusted digital security organization like Access Now’s Digital Security Helpline or, in Serbia, the SHARE Foundation, provides the most reliable assessment.
Does the UK Supreme Court ruling on spyware change anything for Serbian activists?
On July 27, 2026, the UK Supreme Court ruled in Kingdom of Bahrain v Shehabi and Mohammed that a foreign state using spyware against individuals in the United Kingdom cannot claim state immunity to block a civil lawsuit. The case involved Bahraini activists in London whose computers were infected with FinSpy. The court found, by a 3-2 majority, that remote spyware infection constitutes an act carried out in the UK, opening the courthouse door for personal injury claims against foreign governments. For Serbian activists or diaspora members residing in the UK or EU who can show their devices were infected, this ruling represents a meaningful — if difficult — legal pathway. Professor Philippa Webb KC, who represented the claimants, described the judgment’s significance: foreign states “may no longer be able to hide behind state immunity” for spyware attacks on individuals within UK jurisdiction.
Why does Serbia’s EU candidate status matter here?
EU accession candidates are required to demonstrate functioning democratic institutions, rule of law, and respect for fundamental rights — conditions assessed in the European Commission’s annual enlargement reports. The European Parliament, in a 2025 resolution, specifically identified Serbia’s use of spyware against civil society and journalists as a significant concern tied to those accession conditions. The September 2026 forensic findings — documenting ongoing, escalating surveillance by Serbian state agencies against the country’s most prominent pro-democracy movement — give Brussels formal grounds to treat Serbia’s accession trajectory as conditioned on demonstrable accountability for documented surveillance abuses. Whether the European Commission translates that political leverage into concrete accession pressure on Belgrade remains the open question Serbia’s civil society and the student movement are watching most closely.
ⓒ 2026 TECHTIMES.com All rights reserved. Do not reproduce without permission.
