Zero Day Room
Live
News

Pegasus Zero-Click Infects Serbian Activist via Patched iOS

Citizen Lab and SHARE Foundation found a Serbian student activist's iPhone was infected with NSO's Pegasus spyware using a zero-click iMessage exploit

Citizen Lab and SHARE Foundation found a Serbian student activist's iPhone was infected with NSO's Pegasus spyware using...

A Serbian student activist was infected with NSO Group's Pegasus spyware via a zero-click iMessage exploit, according to a forensic investigation by the Citizen Lab and the SHARE Foundation. The Citizen Lab said it found high-confidence indicators of infection on the individual's iPhone in December 2025 and January 2026.

The target, who consented to publication but remains unnamed, received an Apple Threat Notification warning of mercenary spyware targeting. The researchers stated the attack used an iMessage zero-click exploit they believe was patched by Apple in iOS 18.4.1, released in April 2025. A zero-click exploit requires no interaction from the recipient.

Such an infection would be invisible to the target. It grants the attacker total access to the device, including notes, pictures, and encrypted messages. The attacker can also covertly activate the microphone and camera.

Pegasus Campaign Against Serbian Pro-Democracy Groups

The investigation began after the activist received the Apple notification. This notification was among at least 14 documented by the SHARE Foundation involving members of Serbia's student movement, civil society, and an opposition member of parliament. The Citizen Lab linked the targeting to key 2026 election cycles.

The Toronto-based laboratory said this case is part of a longer history of surveillance abuses in Serbia. This includes previous Pegasus targeting of civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware. On September 2, the SHARE Foundation and Amnesty Tech confirmed a new version of NoviSpy was found on another student movement member's device.

The Patched Vulnerability and User Guidance

The Citizen Lab's research, published on September 2, centered on an iMessage zero-click exploit. The laboratory stated it "believed had been patched by Apple as of iOS 18.4.1." This update was released in April 2025.

The laboratory urged all Apple Threat Notification recipients to treat the alert as a presumption of infection and seek expert help immediately. It recommended that close contacts like family members also seek spyware screening. People at heightened risk should enable Apple's Lockdown Mode, and all devices must be kept updated.

Individuals in Serbia were encouraged to contact the SHARE Foundation. Recipients elsewhere were directed to trusted experts like Access Now's Digital Security Helpline. The Citizen Lab pointed to online resources including Security Planner but stressed there is "no substitute for personalized advice."

Forensic work on the other notification cases in Serbia is continuing. The laboratory said this confirmation demonstrates continued targeting of the country's pro-democracy movement with mercenary spyware.

Topics

#News

Related coverage

More from News