
Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia
Recent investigations confirm the use of NSO Group's Pegasus spyware against Serbian student activists via iMessage zero-click exploits. This marks a significant escalation in the use of mercenary surveillance tools within the region.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- Source:
- Citizen Lab
- Read Time:
- 4 min
Executive Summary
In early September 2026, security researchers from the Citizen Lab, in collaboration with the SHARE Foundation, identified a sophisticated surveillance campaign targeting members of the Serbian student protest movement. The investigation confirmed the deployment of NSO Group’s Pegasus spyware, delivered via a zero-click iMessage exploit. This incident represents the largest documented wave of targeted surveillance in the country to date, highlighting the persistent threat posed by mercenary spyware vendors to civil society and political activists.
Threat Analysis
The campaign utilized a zero-click exploit chain that bypassed standard user interaction requirements, allowing the silent installation of Pegasus. By leveraging vulnerabilities in Apple’s iMessage framework, the operators were able to gain full control over the victims' devices, including access to encrypted communications, location data, and microphone/camera feeds. The timing of these infections correlates with periods of heightened political activity, suggesting a strategic effort to monitor and suppress dissent.
Technical Details
The infection vector involved a malicious payload delivered through iMessage, which triggered a memory corruption vulnerability. Once the exploit successfully executed, it established a persistent connection to a command-and-control (C2) infrastructure designed to exfiltrate sensitive data. While Apple addressed the underlying vulnerability in iOS 18.4.1, the persistence of these campaigns underscores the agility of exploit brokers who maintain stockpiles of zero-day and N-day vulnerabilities to target high-value individuals.
Attribution Assessment
While the specific end-user of the Pegasus license remains officially unconfirmed, the nature of the targeting—specifically against domestic political movements—points toward state-aligned actors or government-contracted entities. The use of such high-cost, high-capability tools is consistent with the operational profile of nation-state intelligence services seeking to neutralize internal opposition through clandestine digital monitoring.
Implications
The continued abuse of mercenary spyware poses a critical threat to global human rights and democratic processes. When commercial surveillance tools are deployed against activists, journalists, and political figures, it creates a chilling effect on free speech and assembly. Furthermore, the reliance on telecom signaling vulnerabilities (such as SS7 and Diameter) alongside device-level exploits demonstrates a multi-layered approach to surveillance that is increasingly difficult for standard mobile security solutions to detect.
Recommendations
Organizations and individuals at high risk should adopt a 'zero-trust' approach to mobile security. This includes: 1) Enabling Lockdown Mode on iOS devices to restrict attack surfaces. 2) Regularly auditing device logs for anomalous network traffic. 3) Utilizing encrypted communication platforms that do not rely on standard SMS or vulnerable messaging protocols. 4) Engaging in periodic digital hygiene assessments to identify potential indicators of compromise (IoCs) associated with known mercenary spyware infrastructure.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries

Global Surge in Mercenary Spyware Alerts: Apple Warns Users Across 110 Countries

