Skip to content
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Infosecurity-Magazine September 3, 2026

A member of Serbia's student protest movement has been infected with NSO Group's Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the Foundation.

The Citizen Lab said it found high-confidence indicators of infection on the individual's iPhone across December 2025 and January 2026, but that this did not rule out further infections. The target consented to publication but asked to remain unnamed, and the exact infection date was withheld to protect their privacy.

The September 2 research said the attack used an iMessage zero-click exploit that the Citizen Lab believed had been patched by Apple as of iOS 18.4.1, a version Apple released in April 2025.

A zero-click exploit requires no action from the recipient, allowing spyware to be delivered without the target clicking a link or opening an attachment.

The researchers said such an infection would not have been visible to the target and would give the attacker total access to the device, including notes, pictures and encrypted messages, and the ability to covertly activate the microphone and camera.

Pegasus Targets Serbian Student Movement

The laboratory said the investigation began after the individual received an Apple Threat Notification warning of targeting with mercenary spyware.

The notification was among at least 14 documented by the Foundation involving members of Serbia's student movement and civil society, as well as an opposition member of parliament. The Citizen Lab said the targeting came ahead of key 2026 election cycles.

The Toronto-based laboratory said the case formed part of a longer history of surveillance abuses in Serbia, including Pegasus targeting of civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware.

The Foundation and Amnesty Tech confirmed the same day that a new version of NoviSpy had been found on another student movement member's device.

What Notification Recipients Should Do

The Citizen Lab said an Apple Threat Notification should be treated as presuming infection, and urged recipients to seek expert assistance immediately.

It also recommended that close contacts such as family members and collaborators seek spyware screening, that people at heightened risk enable Apple's Lockdown Mode, and that all devices be kept updated.

Individuals in Serbia were encouraged to the Foundation, while recipients elsewhere were directed to trusted experts such as Access Now's Digital Security Helpline. It said there was no substitute for personalized advice but pointed to online resources including Security Planner.

The laboratory said its forensic work on the other notification cases was continuing, and that the confirmation demonstrated continued targeting of Serbia's pro-democracy movement with mercenary spyware.

Image credits: Tada Images / Poetra.RH / Shutterstock.com

Apple Patches Two Zero-Days Exploited in Pegasus Attacks News 8 September 2023

Apple Patches Two Zero-Days Exploited in Pegasus Attacks

NSO Group's Pegasus Spyware Found on High-Risk iPhones News 18 April 2023

NSO Group's Pegasus Spyware Found on High-Risk iPhones

Pegasus Spyware Used Against Thailand’s Pro-Democracy Movement News 18 July 2022

Pegasus Spyware Used Against Thailand’s Pro-Democracy Movement

WhatsApp Discovers NSO Group-Linked Spearphishing Attempts News 9 June 2026

WhatsApp Discovers NSO Group-Linked Spearphishing Attempts

Polish Prosecutors Step Up Probe into Pegasus Spyware Operation News 24 June 2024

Polish Prosecutors Step Up Probe into Pegasus Spyware Operation

What’s Hot on Infosecurity Magazine?

65% of Enterprises Have Seen AI Agents Act Out of Scope

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

Healthcare Giant McKesson Investigates Data Breach Incident

Manchester Airports Group Hit by Cyber Incident

Attackers Steal METR API Key and Burn $600,000 in AI Credits

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

Manchester Airports Group Hit by Cyber Incident

DDoS Attack Hits Norwegian Government Services

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations

Attackers Steal METR API Key and Burn $600,000 in AI Credits

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How To Enhance Security Operations with AI-Powered Defenses

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Dispelling the Myths of Defense-Grade Cybersecurity

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Attack Types (1)

Countries (2)

Malware (2)

Platforms (2)

Tools (1)