Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist

In collaboration with the SHARE Foundation, the Citizen Lab confirmed that the iPhone of a member of Serbia’s student protest movement was infected with Pegasus spyware.

Date Published

September 2, 2026

In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware. 

Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. We found high-confidence indicators of infection from a period across December 2025 – January 2026, however this does not preclude the possibility of additional infections.  

We believe that the zero-click exploit used in this attack targeted Apple iMessage, and has subsequently been patched by Apple as of iOS 18.4.1.

A zero-click infection with Pegasus spyware would not have been visible to the target, and would give the Pegasus attacker total access to the device. Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages. Pegasus also has the ability to covertly enable the phone’s microphone and camera.

We are confirming the case publicly at the target’s request and with their consent. They have requested to remain unnamed at this time, and we are not specifying the specific infection date and time to protect their privacy.

A Wave of Apple Threat Notifications Targeting Serbia’s Pro-Democracy Movement

The SHARE Foundation has documented at least 14 cases of individuals in Serbia’s student movement and civil society, as well as an opposition Member of Parliament, who recently received Apple Threat Notifications. These notifications and forensic confirmation highlight the aggressive mercenary spyware targeting of the peaceful pro-democracy movement with mercenary spyware ahead of key 2026 election cycles.

Click HERE to read The SHARE Foundation report.

The Citizen Lab continues our forensic investigation of these cases in collaboration with the SHARE Foundation.

An Apple Threat Notification is a high-confidence indicator that a device was targeted for infection with mercenary spyware, and our guidance is that it should be treated as presumed-infected, and that recipients immediately seek expert assistance (See: Got an Apple Threat Notification? Take Action Now).

Serbia: A Growing History of Spyware Abuses

This most recent Pegasus case and wave of Apple Notifications are just the latest in a long series of documented abuses of surveillance technology in Serbia, including previous Pegasus targeting of civil society, as well as the use of Cellebrite forensic tools to plant NoviSpy spyware.

Indeed, The SHARE foundation and Amnesty Tech are also confirming today that a new version of NoviSpy’s Android spyware has been found on the device of a member of the student movement.

Received an Apple Threat Notification? Take Action Now

An Apple Threat Notification is serious, and indicates that you were likely targeted by a government using Pegasus-style mercenary spyware. We encourage you to consult this FAQ on Apple Threat Notifications by Access Now.

If you have received an Apple Threat Notification you should immediately seek expert assistance. Individuals in Serbia that received a notification should get in touch with The SHARE Foundation. We also recommend that recipients of Apple Threat Notifications ensure that close contacts such as family members and collaborators also seek spyware screening.

If you are not in Serbia, but received an Apple Threat Notification, we encourage you to immediately contact trusted experts, such as Access Now’s Digital Security Helpline, which supports members of civil society like human rights defenders, journalists, and dissidents.

At Risk? Use Lockdown Mode on your iPhone

If you believe that you may be targeted with mercenary spyware because of who you are or what you do, we urge you to use optional security features on your iPhone. Apple users can enable Lockdown Mode, which seriously increases the security of your device.

Click HERE for instructions on how to enable Apple’s Lockdown Mode

If you think you may be at risk from mercenary spyware, we encourage you to consult a trusted digital security expert for assistance. There is no substitute for personalized digital security advice, however, you may also find online security resources such as the Security Planner helpful.

Keep Your iPhone Updated!

We believe that the zero-click used in this attack has been rendered ineffective by a patch from Apple in recent iOS versions. We urge everyone, especially those facing increased risks because of who they are or the work they do, to keep all devices updated.

Click HERE for instructions on how to keep your iPhone up to date.