Back Infosecurity-Magazine Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
A member of Serbia's student protest movement has been infected with NSO Group's Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the Foundation.
The Citizen Lab said it found high-confidence indicators of infection on the individual's iPhone across December 2025 and January 2026, but that this did not rule out further infections. The target consented to publication but asked to remain unnamed, and the exact infection date was withheld to protect their privacy.
The September 2 research said the attack used an iMessage zero-click exploit that the Citizen Lab believed had been patched by Apple as of iOS 18.4.1, a version Apple released in April 2025.
A zero-click exploit requires no action from the recipient, allowing spyware to be delivered without the target clicking a link or opening an attachment.
The researchers said such an infection would not have been visible to the target and would give the attacker total access to the device, including notes, pictures and encrypted messages, and the ability to covertly activate the microphone and camera.
Pegasus Targets Serbian Student Movement
The laboratory said the investigation began after the individual received an Apple Threat Notification warning of targeting with mercenary spyware.
The notification was among at least 14 documented by the Foundation involving members of Serbia's student movement and civil society, as well as an opposition member of parliament. The Citizen Lab said the targeting came ahead of key 2026 election cycles.
The Toronto-based laboratory said the case formed part of a longer history of surveillance abuses in Serbia, including Pegasus targeting of civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware.
The Foundation and Amnesty Tech confirmed the same day that a new version of NoviSpy had been found on another student movement member's device.
What Notification Recipients Should Do
The Citizen Lab said an Apple Threat Notification should be treated as presuming infection, and urged recipients to seek expert assistance immediately.
It also recommended that close contacts such as family members and collaborators seek spyware screening, that people at heightened risk enable Apple's Lockdown Mode, and that all devices be kept updated.
Individuals in Serbia were encouraged to the Foundation, while recipients elsewhere were directed to trusted experts such as Access Now's Digital Security Helpline. It said there was no substitute for personalized advice but pointed to online resources including Security Planner.
The laboratory said its forensic work on the other notification cases was continuing, and that the confirmation demonstrated continued targeting of Serbia's pro-democracy movement with mercenary spyware.
Image credits: Tada Images / Poetra.RH / Shutterstock.com
Apple Patches Two Zero-Days Exploited in Pegasus Attacks News 8 September 2023
Apple Patches Two Zero-Days Exploited in Pegasus Attacks
NSO Group's Pegasus Spyware Found on High-Risk iPhones News 18 April 2023
NSO Group's Pegasus Spyware Found on High-Risk iPhones
Pegasus Spyware Used Against Thailand’s Pro-Democracy Movement News 18 July 2022
Pegasus Spyware Used Against Thailand’s Pro-Democracy Movement
WhatsApp Discovers NSO Group-Linked Spearphishing Attempts News 9 June 2026
WhatsApp Discovers NSO Group-Linked Spearphishing Attempts
Polish Prosecutors Step Up Probe into Pegasus Spyware Operation News 24 June 2024
Polish Prosecutors Step Up Probe into Pegasus Spyware Operation
What’s Hot on Infosecurity Magazine?
65% of Enterprises Have Seen AI Agents Act Out of Scope
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Healthcare Giant McKesson Investigates Data Breach Incident
Manchester Airports Group Hit by Cyber Incident
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
Manchester Airports Group Hit by Cyber Incident
DDoS Attack Hits Norwegian Government Services
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Dispelling the Myths of Defense-Grade Cybersecurity
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
