News Room
16
Share
Escalating Mercenary Spyware Crisis: Pegasus and NoviSpy Campaigns Target Serbian Activists
criticalOffensive Tools

Escalating Mercenary Spyware Crisis: Pegasus and NoviSpy Campaigns Target Serbian Activists

A surge in zero-click spyware attacks has hit Serbian student activists, with confirmed infections of NSO Group's Pegasus and the emerging NoviSpy tool. This follows a global wave of Apple threat notifications issued to users across 110 countries.

01 October 2026Last updated 01 October 20264 min readCitizen Lab
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Nation-State
Geography:
Europe
Confidence:
Confirmed
Source:
Citizen Lab
Read Time:
4 min

Executive Summary

In late September 2026, security researchers and human rights organizations confirmed a targeted surveillance campaign against members of the Serbian student protest movement. The campaign utilized highly sophisticated, zero-click exploits, specifically identifying the use of NSO Group’s Pegasus and a secondary, less-documented tool referred to as NoviSpy. This incident occurs against the backdrop of a massive, global increase in mercenary spyware activity, with Apple recently issuing threat notifications to high-risk individuals in 110 countries.

Threat Analysis

The threat landscape for mobile devices has shifted toward 'mercenary' models, where private vendors develop and sell offensive cyber capabilities to state-aligned actors. Unlike traditional malware, these tools are designed for surgical precision, often bypassing standard security measures through zero-click vectors that require no user interaction. The targeting of Serbian activists suggests a coordinated effort to monitor political dissent ahead of upcoming electoral cycles, mirroring tactics observed in other regions where surveillanceware is used to suppress civil society.

Technical Details

The Pegasus infection identified in Serbia utilized a zero-click exploit chain, likely leveraging an undisclosed vulnerability in iOS to achieve remote code execution. Once the device is compromised, the spyware gains full access to the file system, including encrypted messaging databases, real-time location tracking, and microphone/camera activation. NoviSpy, while less understood, appears to function as a modular implant capable of exfiltrating data even when the device is in low-connectivity states, potentially utilizing Bluetooth relay techniques similar to those observed in the 'Manic' Android malware family identified earlier this year.

Attribution Assessment

While NSO Group is the confirmed developer of the Pegasus platform, attribution for the specific deployment remains complex. These tools are typically licensed to government entities, which then operate them under a veil of secrecy. The use of NoviSpy suggests that state actors are diversifying their toolkit, potentially to avoid the detection signatures associated with more well-known platforms like Pegasus. The geographic focus on Serbian political movements points toward domestic or regional state-sponsored intelligence operations.

Implications

The widespread use of these tools poses a critical threat to journalists, activists, and political figures globally. The fact that Apple has had to issue notifications to users in 110 countries underscores the scale of the mercenary spyware market. These tools are no longer limited to high-profile targets but are being deployed against grassroots organizers, effectively chilling political expression and endangering the safety of sources and activists.

Recommendations

  1. Enable 'Lockdown Mode' on all iOS devices if you are in a high-risk category. 2. Regularly audit device logs and utilize tools like the Mobile Verification Toolkit (MVT) to scan for indicators of compromise. 3. Avoid clicking suspicious links and consider using 'Strict Account Settings' on messaging platforms like WhatsApp to limit exposure to unknown contacts. 4. If an Apple threat notification is received, immediately seek assistance from specialized digital security organizations such as the Citizen Lab or local human rights tech support.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo