
Escalating Mercenary Spyware Campaigns: Global Surge in Zero-Click Attacks Targeting Civil Society
Recent intelligence confirms a massive wave of mercenary spyware, including Pegasus and NoviSpy, targeting activists and politicians across 110 countries. This surge highlights the growing sophistication of zero-click exploits used to compromise high-profile mobile devices.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- The Hacker News
- Read Time:
- 4 min
Executive Summary
In mid-August 2026, Apple initiated a global alert campaign, notifying users in 110 countries that they had been targeted by sophisticated mercenary spyware. This follows a broader trend of increased surveillance activity throughout 2026, most notably in Serbia, where researchers from the SHARE Foundation confirmed that student activists and opposition lawmakers were compromised using zero-click exploits. These campaigns represent a significant escalation in the use of private-sector surveillance tools against civil society.
Threat Analysis
The threat landscape is currently dominated by the deployment of high-cost, low-volume mercenary spyware. Unlike traditional malware, these tools are designed for surgical precision, often utilizing zero-click chains that require no user interaction to achieve full device compromise. The recent activity in Serbia, involving both Pegasus and the lesser-known NoviSpy, underscores the multi-vendor approach now favored by state-aligned actors to bypass standard security measures.
Technical Details
These attacks frequently leverage vulnerabilities in core mobile operating system components, such as iMessage or WebKit, to gain kernel-level access. Once the initial exploit is triggered, the spyware establishes a persistent connection to command-and-control (C2) infrastructure, allowing for the exfiltration of encrypted messages, real-time location tracking, and remote microphone/camera activation. The use of 'Manic' Android malware in parallel campaigns targeting financial and government sectors suggests that threat actors are diversifying their toolsets to maintain access across heterogeneous mobile environments.
Attribution Assessment
While Apple maintains a policy of not attributing these attacks to specific nation-states, the geographic distribution and the nature of the targets—journalists, activists, and political figures—strongly suggest state-sponsored or state-sanctioned operations. The denial of involvement by Serbian authorities following the September 2026 report highlights the difficulty in holding state actors accountable for the deployment of commercial spyware.
Implications
The proliferation of these tools poses a critical risk to democratic processes and human rights. The ability of non-state actors to purchase and deploy military-grade surveillance capabilities has democratized espionage, making it accessible to regimes that previously lacked such advanced technical infrastructure. This creates a persistent threat environment where high-value individuals are under constant risk of compromise.
Recommendations
- Enable 'Lockdown Mode' on all Apple devices if you are in a high-risk category (journalists, activists, politicians).
- Regularly update mobile operating systems to the latest security patches to mitigate known exploit chains.
- Exercise extreme caution with unsolicited messages or links, even from known contacts, as zero-click exploits bypass traditional phishing defenses.
- Utilize encrypted communication platforms that support end-to-end verification and consider hardware-based security keys for sensitive accounts.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
