
Escalating Surveillance: Pegasus Zero-Click Exploits Target Civil Society in Eastern Europe
Recent forensic analysis confirms the deployment of advanced zero-click spyware against activists in Serbia. This incident highlights the persistent threat posed by commercial surveillance vendors.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Eastern Europe
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 4 min
Executive Summary
In late September 2026, cybersecurity researchers identified a sophisticated zero-click exploit chain targeting the mobile devices of prominent members of the Serbian student movement. The attack, which utilized advanced spyware consistent with the Pegasus framework, underscores the ongoing proliferation of mercenary surveillance tools. This incident marks a significant escalation in the use of private-sector offensive cyber capabilities against political dissidents in the Balkan region.
Threat Analysis
The targeting of civil society members suggests a coordinated effort to monitor and suppress political mobilization. Unlike traditional phishing-based attacks, this campaign employed a zero-click vector, requiring no user interaction to achieve full device compromise. The persistence of these tools in the hands of non-state actors and regional intelligence services remains a critical concern for global human rights organizations and digital security experts.
Technical Details
The exploit chain leveraged a previously undisclosed vulnerability in the mobile operating system's image processing library. By sending a specially crafted, invisible message to the target's device, the attackers triggered a memory corruption flaw that allowed for arbitrary code execution. Once the initial foothold was established, the spyware deployed a modular payload capable of exfiltrating encrypted messaging data, real-time location tracking, and microphone activation. The command-and-control (C2) infrastructure utilized a series of obfuscated proxy servers to mask the origin of the malicious traffic.
Attribution Assessment
While the specific operator behind this campaign remains under investigation, the technical signature and the nature of the exploit are highly characteristic of commercial spyware platforms. The use of such high-cost, zero-click capabilities is typically restricted to state-aligned entities or well-funded intelligence agencies. The involvement of established exploit brokers, such as those previously sanctioned by the U.S. Treasury, cannot be ruled out as a potential supply chain for these capabilities.
Implications
The continued availability of mercenary spyware to regional actors poses a severe threat to democratic processes and individual privacy. As commercial surveillance vendors continue to outpace traditional nation-state espionage groups in the development of zero-day exploits, the barrier to entry for conducting high-level digital surveillance has significantly lowered. This trend threatens to destabilize regional security and undermines the integrity of mobile communication platforms.
Recommendations
Organizations and individuals at high risk of surveillance should prioritize the use of 'Lockdown Mode' or equivalent security features on their mobile devices. It is imperative to maintain software at the latest patch levels to mitigate known vulnerabilities. Furthermore, civil society groups should engage in regular digital hygiene audits and utilize end-to-end encrypted communication channels that are hardened against metadata analysis. Security teams should monitor for anomalous network traffic patterns that may indicate the presence of unauthorized surveillance agents.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Mercenary Spyware Crisis: Pegasus and NoviSpy Campaigns Target Serbian Activists

Global Surge in Mercenary Spyware Alerts: Apple Warns High-Risk Users Across 110 Countries

