
Mercenary Spyware Resurges in Eastern Europe as Pegasus and NoviSpy Variants Target High-Value Civil Society Targets
Forensic findings reveal active deployments of NSO Group's Pegasus and NoviSpy variants against activists and opposition figures in Serbia. The discovery follows global Apple threat alerts.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- Source:
- Amnesty International / Citizen Lab
- Read Time:
- 3 min
Executive Summary
Recent threat intelligence reporting from digital rights investigators and security researchers has confirmed targeted mobile surveillance campaigns utilizing commercial spyware against civil society in Eastern Europe. Forensic analysis conducted in early September 2026 confirmed that opposition members, student organizers, and political figures in Serbia have been targeted using sophisticated mercenary spyware tools, including Israeli vendor NSO Group's flagship Pegasus implant alongside newly modified variants of NoviSpy. These targeted operations closely follow an unprecedented wave of global Apple threat notifications issued across more than 110 countries, underscoring an accelerating commercial surveillance ecosystem despite international export controls and vendor sanction regimes.
Threat Analysis
Commercial surveillanceware vendors—often referred to as mercenary spyware developers—continue to sell offensive capabilities to state customers seeking intelligence on political opposition, journalists, and activists. In this latest campaign, researchers verified mobile infections involving multi-vector intrusion sets. While commercial surveillance operations are designed to operate with minimal forensic footprints, digital forensic laboratories identified traces of both zero-click remote exploitation and network-facilitated deliveries on targeted iOS and Android handsets. The deployment of multiple disparate tools (Pegasus and NoviSpy) against the same demographic indicates either coordinated inter-agency tasking or multi-vendor acquisition by regional security apparatuses.
Technical Details
Technical artifacts recovered from compromised devices indicate the continued reliance on sophisticated zero-click exploit chains operating against modern mobile operating system protections. At least one compromised iOS device exhibited artifacts indicative of zero-click delivery, bypassing standard user interaction gates to achieve arbitrary code execution within media and messaging parsing frameworks before escalating privileges to root. Once established, both Pegasus and NoviSpy maintain capabilities for persistent local reconnaissance, extracting encrypted messaging databases, executing remote microphone and camera activation, logging keystrokes, and tracking location telemetry. NoviSpy variants have also demonstrated network-level payload adaptation, making payload delivery difficult to distinguish from standard background synchronization services.
Attribution Assessment
While vendor software like Pegasus is definitively developed by NSO Group, operational deployment is attributed to regional intelligence or domestic law enforcement agencies. Citizen Lab and Amnesty International researchers evaluate with high confidence that the operators targeting Serbian opposition figures and student movements represent state-aligned domestic actors utilizing commercial contracts. Commercial brokers and surveillance contractors continue to enable client states to bypass native domestic technical limitations, operationalizing third-party offensive cyber tooling against domestic political adversaries.
Implications
This activity highlights that international blacklists and public exposure have failed to deter authoritarian and hybrid regimes from acquiring commercial surveillance assets. Furthermore, the dual usage of high-cost zero-click exploits (Pegasus) alongside alternative or localized implants (such as NoviSpy) reflects vendor diversification strategies among state actors seeking to hedge against single-vendor operational disruption.
Recommendations
High-risk individuals, government contractors, and enterprise executives operating in politically contentious regions should strictly enforce hardened mobile security postures:
- Enable Apple Lockdown Mode on all managed iOS devices to significantly diminish the attack surface exploited by message-parsing zero-click chains.
- Enforce daily device reboots to flush non-persistent memory-resident implants.
- Regularly verify the authenticity of hardware-level threat alerts through direct vendor channels and engage recognized incident response resources (such as Access Now or Citizen Lab) upon receiving notification.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
