Jump to content

User:Louis/Mercenary spyware targeting of Serbian civil society

From Consumer Rights Wiki

At least 14 people in Serbia's student movement, civil society, and opposition had their own phones silently converted into surveillance devices in 2026, with the attacker able to reach the microphone, camera, photos, and encrypted messages on the device.[1][2] One student activist's iPhone was infected through an iMessage zero-click exploit that carried NSO Group's Pegasus spyware, active across December 2025 to January 2026 and requiring no tap, click, or download by the owner.[2][3] The victims learned they had been hit only because Apple sent mercenary-spyware threat notifications on August 13, 2026 to targeted users in 110 countries, and Serbian recipients then took their phones to forensic analysts.[3][4] The SHARE Foundation called it the largest documented wave of such infection in Serbia to date; investigators could not determine who was responsible, NSO says it sells only to governments, and the Serbian government denied involvement.[3][5]

Forensic findings

[edit | edit source]

The Citizen Lab, working with the SHARE Foundation, analyzed forensic artefacts from the iPhone of a member of Serbia's student protest movement after the owner received an Apple Threat Notification.[2] Its analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware, with high-confidence indicators of infection across December 2025 to January 2026.[2] Bill Marczak, a senior researcher at the Citizen Lab, put the implant on at least one student's phone in that window, and said Apple's security updates have since neutralized the spyware.[3]

A zero-click Pegasus infection is invisible to the target & gives the attacker total access to the device. The Citizen Lab described Pegasus as able to do anything the user can do, from reading notes, pictures, and even encrypted messages, and separately able to covertly enable the phone's microphone and camera.[2] The SHARE Foundation described the same capability: spyware of this kind can reach messages, contacts, photos, app data, and other files, and can secretly record the screen or activate the microphone and camera.[1]

The two forensic labs split the wave by malware type. At least one device was targeted with Pegasus, made by NSO Group, & at least two devices were targeted with malware similar to NoviSpy, an Android tool first exposed by Amnesty International in Serbia in December 2024.[3][6] One of the NoviSpy cases ran on the phone of a student movement member whose device had previously been taken away during police questioning, according to SHARE.[3] Amnesty International, whose Security Lab independently confirmed the SHARE findings, said the 2026 case revealed a new Android tool similar in function to NoviSpy but built with specific efforts to avoid detection.[1]

Two spyware tools in the 2026 wave
Attribute Pegasus NoviSpy
Maker and origin NSO Group, an Israeli company[3] An Android tool first exposed in Serbia by Amnesty International in December 2024[6]
Target device Apple iPhone[2] Android phone[6]
How it reached the phone in this wave An iMessage zero-click exploit needing no tap, click, or download[2] Installed after a phone was taken away during police questioning[3]
Devices confirmed in this wave At least one[3] At least two[3]

Scale and targets

[edit | edit source]

The SHARE Foundation confirmed that at least 14 people in Serbia were targeted with advanced spyware since the beginning of 2026, and named the categories of those hit: members of the student movement, activists, a member of parliament, and a local councilor, all from opposition parties.[1][3] Twelve people contacted SHARE's digital forensics experts in August 2026 after receiving warnings on their phones; the foundation's own analysis later confirmed two more infections with the new NoviSpy variant, bringing the count to at least 14.[1]

The SHARE Foundation reported that at least 14 people in Serbia were targeted with advanced spyware, including members of the student movement, activists, a member of parliament, and a local councilor.[1]

The targeting of an MP and a local councilor sits at the center of why the SHARE Foundation treated the wave as more than an individual privacy breach. Political espionage against elected representatives, in its account, strikes at the equality of political actors and the integrity of the electoral process.[1] A student activist who identified herself only as Milica told a Belgrade news conference that she received a notification in mid-August. She said of the attackers:

They could access the microphone and camera on the phone and turn them on while we shower or speak about private matters. It's not normal to do that; it's not normal that we don't have the right to privacy.[3]

Discovery through Apple threat notifications

[edit | edit source]

The wave surfaced only because of a consumer-facing alert. Apple said it sent threat notifications on August 13, 2026 to targeted users in 110 countries, and that to date it has notified users in more than 150 countries overall since 2021.[3][4] That 110-country figure measures the global reach of a single wave of alerts; Serbia's own documented count is at least 14, and each notification is issued to one individual.[3][1]

Apple describes the notifications as high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, likely because of who they are or what they do.[4] They appear on the iPhone Lock Screen and in Settings, arrive by email from [email protected], and show as a banner at the top of a user's account page after sign-in at account.apple.com.[4] Apple states that it relies solely on internal threat-intelligence information to detect the attacks, and that it does not attribute them, or the resulting notifications, to any specific attackers or geographical regions.[4] The Citizen Lab treats a notification as a high-confidence indicator that a device was targeted and should be presumed infected, with the recipient advised to seek expert help immediately.[2]

Apple's support page describes a threat notification as an alert to a user who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do.[4]

Zero-click exploit on a consumer device

[edit | edit source]

The through-line of this case is an ordinary consumer phone. The device was hacked with a zero-click exploit targeting iMessage, meaning the phone was infected remotely without any knowledge or interaction by the owner.[1] There was nothing for the owner to avoid clicking, no attachment to decline, & no visible symptom afterward.[2][1]

The Citizen Lab said it believes the zero-click exploit used in this attack targeted Apple iMessage & has subsequently been patched by Apple as of iOS 18.4.1.[2] The report names no CVE. Apple's own release notes for iOS 18.4.1, published April 2025, describe a CoreAudio flaw (CVE-2025-31200) & a Pointer Authentication bypass (CVE-2025-31201) that Apple said may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.[7] No source in the public record ties those specific CVEs to the Serbian attack, and they are noted here only as Apple's separate description of what that update fixed.

Apple's release notes for iOS 18.4.1 describe a CoreAudio flaw, CVE-2025-31200, that Apple says may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.[7]

Apple's opt-in Lockdown Mode is the consumer-facing counterweight to this class of attack. Apple introduced Lockdown Mode in 2022 as a feature that shrinks the attack surface mercenary spyware relies on, disabling message attachment types, link previews, & other functionality that zero-click exploits typically abuse.[8] In March 2026, Apple stated that it is not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device.[8] The Citizen Lab urged people who believe they may be targeted to enable Lockdown Mode & to keep their devices updated, describing the exploit as rendered ineffective by a recent Apple patch.[2]

NoviSpy and the 2024 precedent

[edit | edit source]

NoviSpy was first disclosed in December 2024, in an Amnesty International report titled A Digital Prison.[6] The report documented how Cellebrite mobile-forensic products, made by an Israeli company, were used to extract data from the phones of journalists & activists, and how the Serbian police and the Security Information Agency (Bezbedonosno-informativna Agencija, or BIA) used a bespoke Android spyware system, NoviSpy, to covertly infect devices during detention or police interviews.[6] Cellebrite tools were used to unlock a phone before infection & to extract its data afterward.[6]

Amnesty International attributed the 2024 NoviSpy campaign to the BIA. Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, said the forensic evidence proved NoviSpy was installed while Serbian police had possession of the journalist Slaviša Milanov's device, and stated:

Amnesty International attributes the NoviSpy spyware to BIA with high confidence.[6]

That high-confidence attribution is Amnesty International's finding about the 2024 cases. It is a separate question from who operated the 2026 wave, which investigators did not determine.[3] In the 2026 wave, Ó Cearbhaill said the forensic findings showed that Serbian student activists continue to be targeted with invasive spyware.[3]

Political context

[edit | edit source]

The people targeted are drawn from a protest movement that grew out of a mass-casualty disaster. On November 1, 2024, a concrete canopy at the railway station in Novi Sad collapsed onto people beneath it, causing 16 deaths, and set off a nationwide movement for accountability.[9] The SHARE Foundation tied the spyware wave to the electoral calendar: the targeting coincided with the March 29, 2026 local elections held in 10 municipalities, seen as a test of whether student-backed opposition groups could organize against ruling-party politicians.[3] The digital targeting could be a preview of similar action for the parliamentary elections scheduled for October 2026, the group said.[5]

Attribution and responses

[edit | edit source]

Reuters could not determine who was responsible for the alleged infections.[3] NSO Group has said it sells only to governments, and neither the Serbian government nor NSO responded to Reuters' requests for comment.[3] The Citizen Lab attributes the software, Pegasus, to NSO Group by technical indicators; it does not attribute the operation to any entity.[2]

Serbia's parliament speaker, Ana Brnabic, a ranking member of the ruling Serbian Progressive Party, dismissed the claims. Asked by Euronews Serbia whether the activists had been spied on, she answered Absolutely not, and added I do not believe a single word they've (students, SHARE foundation) said.[5] Ana Toskic Cvetinovic, a legal expert with the Partneri Srbija rights watchdog, said use of such software without judicial authorization constitutes a crime under Serbian laws, and that There must be a reasoned court decision. To our knowledge, there is no such thing here.[3]

Commercial spyware industry

[edit | edit source]

NSO Group builds Pegasus & sells it to state clients, and it has been under U.S. sanction since the last decade. On November 3, 2021, the U.S. Commerce Department added NSO Group to its Entity List, citing evidence that the company supplied spyware to foreign governments that used it to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers.[10] The listing imposes a license requirement with a presumption of denial on exports to the company.[10]

The U.S. Commerce Department added NSO Group to the Entity List, citing spyware supplied to foreign governments that used it to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers.[10]

The company has also lost in court & in the courtroom of its own targets. On May 6, 2025, a federal jury ordered NSO to pay a record $167 million for hacking more than 1,000 people through WhatsApp messages, capping six years of litigation.[11] Apple took the opposite path against the same defendant: on September 13, 2024 it asked a court to dismiss its own three-year-old hacking suit against NSO, arguing it might never obtain the most critical files about Pegasus & that its own disclosures could aid NSO and its growing list of rivals.[12] In 2025, an American investment group acquired NSO, though the company still operates out of Israel & under Israeli regulations.[3]

See also

[edit | edit source]

References

[edit | edit source]
  1. 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 "SHARE Foundation: Students and Opposition Politicians Targeted by Spyware". SHARE Foundation. 2026-09-02. Retrieved 2026-09-03.
  2. 2.00 2.01 2.02 2.03 2.04 2.05 2.06 2.07 2.08 2.09 2.10 2.11 "Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist". The Citizen Lab. 2026-09-02. Retrieved 2026-09-03.
  3. 3.00 3.01 3.02 3.03 3.04 3.05 3.06 3.07 3.08 3.09 3.10 3.11 3.12 3.13 3.14 3.15 3.16 3.17 3.18 3.19 3.20 Vicens, AJ (2026-09-03). "More than a dozen Serbians targeted with mercenary spyware, digital rights group says". Daily Maverick. Retrieved 2026-09-03.
  4. 4.0 4.1 4.2 4.3 4.4 4.5 "About Apple threat notifications and protecting against mercenary spyware". Apple Support. 2026-08-13. Retrieved 2026-09-03.
  5. 5.0 5.1 5.2 "Spyware targets more than a dozen Serbians ahead of elections". TVP World. 2026-09-03. Retrieved 2026-09-03.
  6. 6.0 6.1 6.2 6.3 6.4 6.5 6.6 "Serbia: Authorities using spyware and Cellebrite forensic extraction tools to hack journalists and activists". Amnesty International. 2024-12-16. Retrieved 2026-09-03.
  7. 7.0 7.1 "About the security content of iOS 18.4.1 and iPadOS 18.4.1". Apple Support. 2025-04-18. Retrieved 2026-09-03.
  8. 8.0 8.1 Shapira, Elad (2026-08-20). "If Apple says your iPhone was targeted by mercenary spyware, treat it like an incident". Jamf. Retrieved 2026-09-03.
  9. Reves, Aleksandra (2025-10-30). "How the Novi Sad Station Disaster Changed a Serbian City". Balkan Insight. Retrieved 2026-09-03.
  10. 10.0 10.1 10.2 "Commerce Adds NSO Group and Other Foreign Companies to Entity List for Malicious Cyber Activities". U.S. Department of Commerce. 2021-11-03. Retrieved 2026-09-03.
  11. Menn, Joseph (2025-05-06). "Spyware-maker NSO ordered to pay $167 million for hacking WhatsApp". The Washington Post. Retrieved 2026-09-03.
  12. Menn, Joseph (2024-09-13). "Apple seeks to drop its lawsuit against Israeli spyware pioneer NSO". The Washington Post. Retrieved 2026-09-03.