Skip to main content
cybersecurity

Pegasus Spyware Infected Serbian Student Activist’s iPhone Through iMessage Zero-Click Exploit

Citizen Lab confirmed that Pegasus spyware infected the iPhone of a Serbian student activist through an iMessage zero-click exploit, highlighting continued surveillance risks for civil society and pro-democracy groups.

Xcademia Team

Xcademia Research Team

Sep 03, 20266 min read4 views
Share:
Pegasus Spyware Infected Serbian Student Activist’s iPhone Through iMessage Zero-Click Exploit

Pegasus Infection Confirmed on Serbian Student Activist’s iPhone

The Citizen Lab, working with the SHARE Foundation, has confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware.

The investigation followed an Apple Threat Notification warning the individual that their device had been targeted with mercenary spyware. Researchers then examined forensic evidence from the iPhone and identified high-confidence indicators of Pegasus infection.

The case is particularly significant because researchers determined that the infection involved a zero-click exploit targeting Apple iMessage. A zero-click attack does not require the victim to click a malicious link, open an attachment or otherwise interact with the attacker.

Citizen Lab identified evidence of infection spanning December 2025 through January 2026, while noting that the available evidence does not rule out additional infections.


How the iMessage Zero-Click Attack Worked

The investigation indicates that the attacker exploited iMessage to deliver Pegasus without requiring visible interaction from the target.

At a high level, the attack chain can be understood as:

Targeted iPhone

Malicious iMessage delivery

Zero-click exploitation

Pegasus installation

Device compromise

Because the victim does not need to interact with the malicious message, traditional user-awareness measures such as avoiding suspicious links may not be sufficient against this class of attack.

Citizen Lab said the exploit was subsequently addressed by Apple in iOS 18.4.1.

info-1


What Pegasus Access Means

According to Citizen Lab, a successful zero-click Pegasus infection would not have been visible to the target.

The spyware can provide extensive access to information and functions on a compromised device. Citizen Lab states that Pegasus can access private information including notes, photographs and encrypted messages. It can also covertly activate the device's microphone and camera.

This makes mercenary spyware fundamentally different from many conventional malware campaigns. The objective is not necessarily to disrupt the device or display an obvious infection message. Instead, the compromise can operate covertly while allowing an attacker to obtain information from the device.

For journalists, activists and other individuals handling sensitive communications, this creates a particularly serious security concern.


Serbia Faces a Broader Wave of Spyware Targeting

The confirmed Pegasus infection is not an isolated notification.

The SHARE Foundation has documented at least 14 cases involving people connected to Serbia's student movement and civil society, along with an opposition Member of Parliament, who received Apple Threat Notifications.

Citizen Lab describes the notifications and forensic confirmation as evidence of aggressive mercenary spyware targeting of Serbia's peaceful pro-democracy movement.

The organisation is continuing its forensic investigation of these cases together with the SHARE Foundation.

info-2


Serbia's Longer History of Surveillance Abuse

Citizen Lab places the latest Pegasus case within a wider history of surveillance technology abuse in Serbia.

The organisation has previously documented spyware targeting involving Serbian civil society. It has also reported the use of Cellebrite forensic tools in connection with the planting of NoviSpy spyware.

In the latest investigation, Citizen Lab also notes that the SHARE Foundation and Amnesty Tech identified a new version of NoviSpy Android spyware on the device of another member of the student movement.

The combination of these findings suggests that spyware concerns in Serbia extend beyond a single surveillance technology or mobile platform.


Apple Threat Notifications Are a Critical Warning

Apple Threat Notifications are particularly important in cases involving highly targeted mercenary spyware.

Citizen Lab describes an Apple Threat Notification as a high-confidence indication that a device was targeted for infection with mercenary spyware. Its guidance is that recipients should treat the warning seriously and seek expert assistance.

For people in Serbia who receive such notifications, Citizen Lab recommends contacting the SHARE Foundation.

For individuals elsewhere, it recommends seeking assistance from trusted organisations such as Access Now's Digital Security Helpline, particularly for journalists, human rights defenders and other members of civil society.


Lockdown Mode Can Add Protection

Citizen Lab also recommends Apple's Lockdown Mode for people who believe they may face targeted mercenary spyware attacks.

Lockdown Mode is an optional security feature designed for individuals who may be exposed to highly sophisticated digital attacks. Citizen Lab recommends that people at elevated risk consider enabling it and seek personalised advice from a trusted digital security professional.

However, the organisation stresses that security advice should be tailored to the individual's circumstances.


Keep Devices Updated

One of the clearest defensive recommendations from the investigation is also one of the simplest: keep devices updated.

Citizen Lab believes the zero-click exploit identified in this case was rendered ineffective by Apple's security updates, including the patch delivered in iOS 18.4.1.

For high-risk users, delayed software updates can leave devices exposed to vulnerabilities that may already have been addressed by the vendor.

Keeping operating systems and applications current therefore remains an important baseline security measure.

info-3


What Enterprises and High-Risk Users Should Take Away

The Serbian case illustrates an important distinction between ordinary cybercrime and highly targeted surveillance.

A conventional phishing campaign often depends on convincing someone to click a link, download a file or provide credentials. A zero-click spyware attack can bypass that interaction entirely.

The announcement highlights a broader industry shift toward attacks that target vulnerabilities in trusted communication platforms rather than relying exclusively on social engineering.

For enterprises, journalists, civil society organisations and individuals handling sensitive information, this reinforces several practical priorities:

  • Maintain current operating-system versions and security patches.

  • Take Apple Threat Notifications seriously.

  • Consider Lockdown Mode when the threat model warrants it.

  • Seek specialist forensic assistance after a suspected targeted attack.

  • Consider the security of close contacts and collaborators.

  • Avoid assuming that lack of suspicious user activity means a device is uncompromised.

These measures do not guarantee protection against sophisticated spyware, but they can improve security posture and help affected individuals respond more quickly.


The Bigger Cybersecurity Picture

The Pegasus case in Serbia demonstrates why mercenary spyware remains an important cybersecurity and human-rights issue.

The confirmed infection involved a sophisticated zero-click attack against an iPhone, while the broader investigation has identified multiple Apple Threat Notifications involving people associated with Serbia's student movement and civil society.

The case also demonstrates the value of independent forensic analysis. An Apple warning provided an important initial signal, while examination of device evidence allowed researchers to establish that Pegasus infection had actually occurred.

For high-risk users, the lesson is straightforward: advanced surveillance attacks may leave little visible evidence, so security alerts, software updates and specialist investigation can play an important role in identifying and responding to compromise.

Additional details about the suspected operator behind this particular infection were not disclosed in the Citizen Lab announcement.

#PegasusSpyware#Spyware#Cybersecurity#ZeroClick#iMessage#AppleSecurity#MobileSecurity#TargetedSurveillance

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, with optional Career+ support.