News Room
16
Share
Mercenary Spyware Resurges in Eastern Europe as Pegasus and NoviSpy Variants Target High-Value Civil Society Targets
highOffensive Tools

Mercenary Spyware Resurges in Eastern Europe as Pegasus and NoviSpy Variants Target High-Value Civil Society Targets

Forensic findings reveal active deployments of NSO Group's Pegasus and NoviSpy variants against activists and opposition figures in Serbia. The discovery follows global Apple threat alerts.

05 September 2026Last updated 05 September 20263 min readAmnesty International / Citizen Lab
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
High
Actor Type:
Nation-State
Geography:
Eastern Europe
Confidence:
Confirmed
Source:
Amnesty International / Citizen Lab
Read Time:
3 min

Executive Summary

Recent threat intelligence reporting from digital rights investigators and security researchers has confirmed targeted mobile surveillance campaigns utilizing commercial spyware against civil society in Eastern Europe. Forensic analysis conducted in early September 2026 confirmed that opposition members, student organizers, and political figures in Serbia have been targeted using sophisticated mercenary spyware tools, including Israeli vendor NSO Group's flagship Pegasus implant alongside newly modified variants of NoviSpy. These targeted operations closely follow an unprecedented wave of global Apple threat notifications issued across more than 110 countries, underscoring an accelerating commercial surveillance ecosystem despite international export controls and vendor sanction regimes.

Threat Analysis

Commercial surveillanceware vendors—often referred to as mercenary spyware developers—continue to sell offensive capabilities to state customers seeking intelligence on political opposition, journalists, and activists. In this latest campaign, researchers verified mobile infections involving multi-vector intrusion sets. While commercial surveillance operations are designed to operate with minimal forensic footprints, digital forensic laboratories identified traces of both zero-click remote exploitation and network-facilitated deliveries on targeted iOS and Android handsets. The deployment of multiple disparate tools (Pegasus and NoviSpy) against the same demographic indicates either coordinated inter-agency tasking or multi-vendor acquisition by regional security apparatuses.

Technical Details

Technical artifacts recovered from compromised devices indicate the continued reliance on sophisticated zero-click exploit chains operating against modern mobile operating system protections. At least one compromised iOS device exhibited artifacts indicative of zero-click delivery, bypassing standard user interaction gates to achieve arbitrary code execution within media and messaging parsing frameworks before escalating privileges to root. Once established, both Pegasus and NoviSpy maintain capabilities for persistent local reconnaissance, extracting encrypted messaging databases, executing remote microphone and camera activation, logging keystrokes, and tracking location telemetry. NoviSpy variants have also demonstrated network-level payload adaptation, making payload delivery difficult to distinguish from standard background synchronization services.

Attribution Assessment

While vendor software like Pegasus is definitively developed by NSO Group, operational deployment is attributed to regional intelligence or domestic law enforcement agencies. Citizen Lab and Amnesty International researchers evaluate with high confidence that the operators targeting Serbian opposition figures and student movements represent state-aligned domestic actors utilizing commercial contracts. Commercial brokers and surveillance contractors continue to enable client states to bypass native domestic technical limitations, operationalizing third-party offensive cyber tooling against domestic political adversaries.

Implications

This activity highlights that international blacklists and public exposure have failed to deter authoritarian and hybrid regimes from acquiring commercial surveillance assets. Furthermore, the dual usage of high-cost zero-click exploits (Pegasus) alongside alternative or localized implants (such as NoviSpy) reflects vendor diversification strategies among state actors seeking to hedge against single-vendor operational disruption.

Recommendations

High-risk individuals, government contractors, and enterprise executives operating in politically contentious regions should strictly enforce hardened mobile security postures:

  • Enable Apple Lockdown Mode on all managed iOS devices to significantly diminish the attack surface exploited by message-parsing zero-click chains.
  • Enforce daily device reboots to flush non-persistent memory-resident implants.
  • Regularly verify the authenticity of hardware-level threat alerts through direct vendor channels and engage recognized incident response resources (such as Access Now or Citizen Lab) upon receiving notification.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo