News Room
16
Share
New Pegasus Zero-Click Exploits Target Activists as Global Mercenary Spyware Campaigns Intensify
criticalOffensive Tools

New Pegasus Zero-Click Exploits Target Activists as Global Mercenary Spyware Campaigns Intensify

Recent intelligence confirms a surge in zero-click Pegasus infections targeting political activists, including a high-profile case in Serbia. Apple has responded by enhancing on-device threat notifications.

18 September 2026Last updated 18 September 20264 min readThe Hacker News
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
Source:
The Hacker News
Read Time:
4 min

Executive Summary

In the last 48 hours, security researchers have confirmed a new wave of zero-click exploits targeting high-risk individuals, specifically members of civil society and political movements. The latest incident involves the infection of a Serbian student movement member’s iPhone via the notorious Pegasus spyware. This follows a broader trend of increased surveillance activity, prompting Apple to overhaul its threat notification system to provide direct, high-confidence alerts on user lock screens.

Threat Analysis

Mercenary spyware remains a critical threat to global security, with exploit brokers and state-aligned actors continuously refining their delivery mechanisms. The shift toward zero-click exploits—which require no user interaction—has made detection significantly more difficult for the average user. These campaigns are increasingly targeting journalists, diplomats, and activists, often utilizing sophisticated chains that bypass standard iOS security protections.

Technical Details

The recent Pegasus campaign utilizes a zero-click exploit chain that leverages vulnerabilities in core iOS components to achieve arbitrary code execution. Once the initial payload is delivered, the spyware establishes persistence, allowing for the exfiltration of encrypted messaging data, real-time location tracking, and microphone/camera access. Unlike traditional malware, these tools are designed to leave minimal forensic footprints, often residing in volatile memory to evade standard mobile security software.

Attribution Assessment

While the specific operator behind the Serbian incident remains under investigation, the use of Pegasus points to a state-sponsored entity or a high-tier government client. The proliferation of such tools is exacerbated by exploit brokers like the recently sanctioned 'Operation Zero' network, which has been linked to the acquisition of proprietary U.S. government cyber tools. The intersection of commercial spyware and state-level intelligence operations continues to blur the lines of attribution.

Implications

The widespread use of mercenary spyware against political figures and activists undermines democratic processes and individual privacy. The fact that even members of the European Parliament investigating these very tools have been targeted highlights the brazen nature of these actors. As these tools become more accessible through the black market, the risk to global financial and government infrastructure grows exponentially.

Recommendations

  1. Enable 'Lockdown Mode' on all iOS devices for high-risk individuals. 2. Regularly update devices to the latest firmware to patch known zero-day vulnerabilities. 3. Monitor Apple’s new on-device threat notifications and seek professional forensic assistance if an alert is received. 4. Avoid clicking suspicious links or interacting with unknown attachments, even if the device is supposedly 'secure'.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo