Pegasus Spyware Infects iPhone in Serbia via Zero-Click

Pegasus Spyware Infects iPhone in Serbia via Zero-Click

Citizen Lab and the SHARE Foundation confirm NSO Group's Pegasus spyware infected a Serbian activist's iPhone through an iMessage zero-click exploit Apple patch…

Researchers from the Citizen Lab and the SHARE Foundation have confirmed that NSO Group's Pegasus spyware infected the iPhone of a member of Serbia's student protest movement through an iMessage zero-click exploit. A zero-click exploit is a hacking technique that compromises a device without the owner needing to tap a link, open an attachment, or take any action at all; simply receiving a specially crafted message can be enough. iMessage is Apple's built-in messaging service for iPhone, iPad, and Mac. Pegasus is a powerful commercial spyware product sold by NSO Group that can silently monitor a device.

Citizen Lab said the attack used an iMessage zero-click exploit, and its analysis found high-confidence indicators of infection during the period from December 2025 to January 2026, while noting that additional infections cannot be ruled out. The specific iMessage flaw exploited in this case has been addressed by Apple in iOS 18.4.1, which was released in April 2025. This means that devices running iOS 18.4.1 or later should be protected from this particular exploitation path, though spyware vendors continually look for new flaws.

The discovery follows Apple sending a new set of threat notifications to customers it suspected may have been targeted by mercenary spyware attacks. The alerts went to an unspecified number of users in 110 countries. Mercenary spyware refers to commercial surveillance software sold to governments or other clients for targeted monitoring, often without the target's knowledge or consent. Apple's threat notifications are designed to warn people who may be individually targeted because of who they are or what they do.

The SHARE Foundation confirmed that at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026. The targets included student movement members, activists, a member of parliament, and a local councilor from opposition parties. The timing of these incidents coincided with local elections held on March 29, 2026. In a separate incident, another student movement member had their phone compromised with a new version of the NoviSpy Android spyware after the device was confiscated during police questioning. NoviSpy is a known Android spyware tool that can quietly steal private data from a phone. Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, said the forensic findings prove Serbian students continue to be targeted with invasive Android spyware tools installed while detained by authorities. He added that the latest 2026 case reveals a new Android spyware similar in functionality to NoviSpy, but newly built with specific efforts to avoid detection by security experts.

SHARE said the same spyware strain has been detected on a second device, after private Viber messages from that phone were disclosed live on Informer TV, a Serbian pro-government news and media television channel. The development is the latest in a string of documented abuses of surveillance technology in the country, including the use of Cellebrite forensic tools to deploy NoviSpy. Forensic tools are software or hardware used by investigators to extract data from devices, but they can also be misused to install spyware without the owner's knowledge.

For people who may be at risk because of who they are and what they do, the researchers and technology vendors offer specific protections. Users should keep their devices up-to-date and consider enabling Lockdown Mode on iOS. Lockdown Mode is an iPhone setting that blocks many advanced features to make it harder for spyware to get in. Google offers an Advanced Protection Program to safeguard Android users with high visibility and sensitive information from targeted online attacks; this program requires a physical security key to sign in, making account takeover much harder. Earlier this year, Meta-owned WhatsApp announced a feature called Strict Account Settings to protect users against advanced cyber attacks by automatically locking certain settings to the most restrictive options, while blocking attachments and media from people not in a user's contact list.

For businesses and IT teams, AEU-I's security-first IT, infrastructure, and consulting services can help review device and network hardening practices against targeted surveillance tools like the ones described here. This reporting is based on findings from Citizen Lab, the SHARE Foundation, and Amnesty International, not on any AEU involvement in these incidents.

How to Protect Yourself

  1. Update your iPhone to iOS 18.4.1 or later, because this version contains Apple's fix for the iMessage flaw used in this attack.
  2. If you are a journalist, activist, or anyone who may be targeted, turn on Lockdown Mode on your iPhone by going to Settings > Privacy & Security > Lockdown Mode.
  3. On an Android phone, enroll in Google's Advanced Protection Program and use a physical security key to stop attackers from taking over your account.
  4. In WhatsApp, open Settings and enable Strict Account Settings to automatically lock restrictive options and block attachments from unknown contacts.
  5. Never connect your phone to a computer or cable you do not control, especially if you have been detained or questioned, and avoid unlocking it for others.
  6. Back up important data regularly and consider using a separate, clean phone for high-risk activities.

Terms Explained

  • zero-click exploit A type of attack that infects a device without needing the owner to tap or click anything, often through a message or call.
  • spyware Software that secretly watches what you do on a device, such as reading messages or tracking your location.
  • iMessage Apple's built-in messaging service for iPhone, iPad, and Mac.
  • Lockdown Mode An iPhone setting that blocks many advanced features to make it harder for spyware to get in.
  • Advanced Protection Program Google's extra security setting that requires a physical security key to sign in, making account takeover much harder.
  • NoviSpy A known Android spyware tool that can quietly steal private data from a phone.
  • forensic tools Software or hardware used by investigators to extract data from devices, which can also be misused to install spyware.
  • mercenary spyware Commercial spying software sold to governments or other clients for targeted surveillance, often without consent.

Related AEU services

  • AEU-I IT and security consulting