News Room
16
Share
Escalating Mercenary Spyware Campaigns: Global Surge in Zero-Click Attacks Targeting Civil Society
criticalOffensive Tools

Escalating Mercenary Spyware Campaigns: Global Surge in Zero-Click Attacks Targeting Civil Society

Recent intelligence confirms a massive wave of mercenary spyware, including Pegasus and NoviSpy, targeting activists and politicians across 110 countries. This surge highlights the growing sophistication of zero-click exploits used to compromise high-profile mobile devices.

16 September 2026Last updated 16 September 20264 min readThe Hacker News
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
Source:
The Hacker News
Read Time:
4 min

Executive Summary

In mid-August 2026, Apple initiated a global alert campaign, notifying users in 110 countries that they had been targeted by sophisticated mercenary spyware. This follows a broader trend of increased surveillance activity throughout 2026, most notably in Serbia, where researchers from the SHARE Foundation confirmed that student activists and opposition lawmakers were compromised using zero-click exploits. These campaigns represent a significant escalation in the use of private-sector surveillance tools against civil society.

Threat Analysis

The threat landscape is currently dominated by the deployment of high-cost, low-volume mercenary spyware. Unlike traditional malware, these tools are designed for surgical precision, often utilizing zero-click chains that require no user interaction to achieve full device compromise. The recent activity in Serbia, involving both Pegasus and the lesser-known NoviSpy, underscores the multi-vendor approach now favored by state-aligned actors to bypass standard security measures.

Technical Details

These attacks frequently leverage vulnerabilities in core mobile operating system components, such as iMessage or WebKit, to gain kernel-level access. Once the initial exploit is triggered, the spyware establishes a persistent connection to command-and-control (C2) infrastructure, allowing for the exfiltration of encrypted messages, real-time location tracking, and remote microphone/camera activation. The use of 'Manic' Android malware in parallel campaigns targeting financial and government sectors suggests that threat actors are diversifying their toolsets to maintain access across heterogeneous mobile environments.

Attribution Assessment

While Apple maintains a policy of not attributing these attacks to specific nation-states, the geographic distribution and the nature of the targets—journalists, activists, and political figures—strongly suggest state-sponsored or state-sanctioned operations. The denial of involvement by Serbian authorities following the September 2026 report highlights the difficulty in holding state actors accountable for the deployment of commercial spyware.

Implications

The proliferation of these tools poses a critical risk to democratic processes and human rights. The ability of non-state actors to purchase and deploy military-grade surveillance capabilities has democratized espionage, making it accessible to regimes that previously lacked such advanced technical infrastructure. This creates a persistent threat environment where high-value individuals are under constant risk of compromise.

Recommendations

  1. Enable 'Lockdown Mode' on all Apple devices if you are in a high-risk category (journalists, activists, politicians).
  2. Regularly update mobile operating systems to the latest security patches to mitigate known exploit chains.
  3. Exercise extreme caution with unsolicited messages or links, even from known contacts, as zero-click exploits bypass traditional phishing defenses.
  4. Utilize encrypted communication platforms that support end-to-end verification and consider hardware-based security keys for sensitive accounts.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo