The discovery of Pegasus spyware on the iPhone of a Serbian student protester has raised alarm bells among cybersecurity experts. The Citizen Lab, in collaboration with the SHARE Foundation, confirmed that the device was compromised using a zero-click exploit targeting Apple’s iMessage service. The infection was likely active from December 2025 to January 2026, although additional instances of infection cannot be ruled out.
Zero-Click Exploit: A Hidden Threat
The zero-click exploit used in this attack was specifically aimed at Apple iMessage. Apple addressed this vulnerability with the release of iOS 18.4.1 in April 2025. Despite this fix, the recent findings highlight ongoing risks as Apple issued threat notifications to numerous users across 110 countries, warning them of potential spyware attacks.
The SHARE Foundation has confirmed that at least 14 individuals in Serbia, including activists, student movement members, and political figures, have been targeted by advanced spyware tools since the beginning of 2026. The timing of these attacks coincided with local elections held on March 29, 2026, raising concerns about the potential political motivations behind the surveillance.
Android Devices Also at Risk
In addition to iOS vulnerabilities, Serbian authorities have been found deploying spyware on Android devices. A student protester’s phone was compromised with a new variant of the NoviSpy Android spyware after being seized during police interrogation. This case underlines the persistent threat posed by Android spyware, which has been tailored to avoid detection by security experts.
Further investigations revealed the same spyware was detected on another device, resulting in private Viber messages being broadcasted on Informer TV, a pro-government media outlet in Serbia. These breaches illustrate the extensive use of surveillance technology in the country, including tools like Cellebrite, which have reportedly been used to deploy NoviSpy.
Staying Secure in a Digital Age
With spyware threats on the rise, individuals at risk due to their roles or activities must ensure their devices are regularly updated. Enabling Lockdown Mode on iOS and participating in Google’s Advanced Protection Program for Android can offer additional layers of security. This year, WhatsApp introduced Strict Account Settings to protect users from sophisticated cyber attacks by automatically applying the most restrictive settings.
These developments underscore the importance of staying vigilant against cyber threats, particularly for those in high-risk roles. As surveillance technologies evolve, so must the measures to combat them, ensuring privacy and security in an increasingly digital world.
