
Citizen Lab Uncovers Pegasus Zero-Click Exploits and NoviSpy Targeting Civil Society in Serbia
Forensic findings reveal zero-click iMessage exploits delivering NSO Group's Pegasus and reconstructed NoviSpy implants against civil society figures amid global mercenary spyware warnings.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Europe
- Confidence:
- Confirmed
- Source:
- Citizen Lab
- Read Time:
- 4 min
Executive Summary
On September 3, 2026, researchers at The Citizen Lab, in collaboration with Amnesty International's Security Lab and the SHARE Foundation, released forensic findings detailing an aggressive surveillance campaign targeting civil society activists in Serbia. The joint investigation confirmed the compromise of an activist's iPhone using NSO Group's Pegasus mercenary spyware via a zero-click exploit chain targeting Apple iMessage, alongside detections of a rebuilt variant of NoviSpy deployed against Android endpoints. The disclosures follow Apple's August threat notification wave, which alerted targeted users across 110 countries.
Threat Analysis
The campaign reflects a sophisticated, dual-track deployment of offensive cyber surveillance tooling. While NSO Group's Pegasus represents elite commercial spyware targeting iOS, the operators concurrently leveraged NoviSpy, an Android-focused malware strain previously tied to domestic surveillance apparatuses. High-confidence infection artifacts confirm active Pegasus exploitation spanning December 2025 through January 2026. The technical capability to deploy zero-click exploits remotely—requiring no user interaction or credential compromise—demonstrates the continued vitality of the private vulnerability broker and commercial exploit market.
Technical Details
The Pegasus infection vector was determined to be a zero-click remote exploit delivered through Apple iMessage. The exploit chain bypassed standard platform defenses before Apple deployed patches in iOS 18.4.1. Once resident, Pegasus establishes persistent in-memory and kernel-level inspection, intercepting encrypted messaging applications (such as Signal and WhatsApp), activating microphones and cameras silently, and extracting device geolocation, photos, and keychains.
Parallel forensic investigations by Amnesty International uncovered a new variant of NoviSpy on Android devices. This variant was rewritten to neutralize signature-based detections established after the initial 2024 campaign. Historical NoviSpy command-and-control (C2) telemetry had resolved to infrastructure linked to state surveillance entities, operating alongside hardware forensics suites such as Cellebrite for local physical extraction.
Attribution Assessment
Attribution for the Pegasus implant points directly to customers of the Israel-based commercial surveillance firm NSO Group. The simultaneous operational deployment of reconstructed NoviSpy samples strongly suggests domestic intelligence involvement, specifically targeting political dissidents, protest coordinators, and investigative journalists. Analysts assess with high confidence that the operators represent state-aligned security agencies exercising surveillance capabilities acquired through commercial contractors and specialized exploit brokers.
Implications
The findings illustrate that zero-day mobile exploit chains remain a primary weapon against high-value targets despite rapid patch cycles by operating system vendors. The proliferation of mercenary spyware to regional intelligence bodies highlights enforcement gaps in international export controls. Furthermore, the dual usage of high-tier zero-click exploits and regional custom Android tooling showcases a mature tiered-surveillance ecosystem accessible to state actors.
Recommendations
- Deploy Mobile Protections: High-risk personnel, executives, and journalists must activate Apple's Lockdown Mode and Google's Advanced Protection Program, which significantly restrict iMessage parsing, sandbox execution, and untrusted network assets.
- Verify Platform Alerts: Ensure all personnel recognize authentic Apple and Google threat alerts, verifying notifications via native platform portals rather than third-party communication.
- Strict Messaging Policies: Enforce application lockdown configurations, such as WhatsApp's Strict Account Settings, to discard incoming attachments and media from unknown senders.
- Aggressive OS Patch Management: Maintain zero-tolerance policies for deferred mobile operating system updates to ensure critical zero-click and memory corruption patches are deployed immediately.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Mercenary Spyware Resurgence: Pegasus and NoviSpy Wave Targets Civil Society in Southeastern Europe

Serbian Civil Society Targeted by Pegasus Zero-Click Exploits Ahead of National Elections

