News Room
16
Share
Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts Across 110 Countries
criticalOffensive Tools

Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts Across 110 Countries

Apple has initiated a massive wave of threat notifications to users in 110 countries, warning of sophisticated mercenary spyware targeting high-profile individuals. This follows recent discoveries of state-linked surveillance campaigns in Serbia and beyond.

17 September 2026Last updated 17 September 20264 min readApple / SHARE Foundation
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
Source:
Apple / SHARE Foundation
Read Time:
4 min

Executive Summary

In mid-August 2026, Apple escalated its defensive posture against state-sponsored surveillance by issuing a fresh round of threat notifications to users across 110 countries. These alerts, which now appear directly on the device's lock screen, signify that the company has high-confidence evidence of individual targeting by mercenary spyware. This development coincides with reports from the SHARE Foundation regarding a significant surge in the use of Pegasus and the previously less-documented 'NoviSpy' tool against activists and politicians in Serbia.

Threat Analysis

Mercenary spyware represents the pinnacle of digital espionage, characterized by extreme cost, high technical sophistication, and the ability to bypass standard security measures. Unlike commodity malware, these tools are typically sold to government entities to monitor journalists, political dissidents, and diplomats. The recent activity in Serbia, where at least 14 high-profile individuals were targeted, highlights the growing accessibility of these tools for regional intelligence agencies. The emergence of 'NoviSpy' alongside established platforms like Pegasus suggests a diversification of the exploit broker market.

Technical Details

These spyware platforms often leverage zero-click exploits, allowing for full device compromise without user interaction. Once installed, the software gains kernel-level access, enabling the exfiltration of encrypted messaging data, real-time location tracking, and remote activation of microphones and cameras. Apple’s new on-device notification system is designed to bypass the limitations of email-based alerts, which are often ignored or filtered. The integration of these alerts into the iOS Lock Screen and Settings menu reflects a shift toward more aggressive user-protection strategies in response to the persistent nature of these threats.

Attribution Assessment

While Apple maintains a policy of not attributing these attacks to specific nation-states, the nature of the targets—activists, opposition lawmakers, and journalists—strongly points to state-sponsored actors. In the Serbian context, local authorities have denied involvement, yet the scale of the campaign suggests a coordinated effort by entities with significant financial and technical resources. The use of multiple spyware families indicates that attackers are likely sourcing tools from various exploit brokers to ensure redundancy and evade detection.

Implications

The global nature of these alerts underscores that no region is immune to mercenary surveillance. The democratization of these tools means that even smaller intelligence agencies can now conduct high-level espionage. This creates a volatile environment for civil society, where the digital privacy of activists is increasingly under siege by state-backed actors using commercial-grade exploits.

Recommendations

Users who receive Apple threat notifications should immediately enable 'Lockdown Mode' on their devices, which restricts certain features to minimize the attack surface. Organizations and high-risk individuals should conduct regular security audits, avoid clicking suspicious links, and consider using hardware security keys. Furthermore, it is critical to keep all software updated to the latest versions to ensure that known vulnerabilities are patched against potential exploit chains.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo