
New Pegasus Zero-Click Exploits Target Activists as Global Mercenary Spyware Campaigns Intensify
Recent intelligence confirms a surge in zero-click Pegasus infections targeting political activists, including a high-profile case in Serbia. Apple has responded by enhancing on-device threat notifications.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- The Hacker News
- Read Time:
- 4 min
Executive Summary
In the last 48 hours, security researchers have confirmed a new wave of zero-click exploits targeting high-risk individuals, specifically members of civil society and political movements. The latest incident involves the infection of a Serbian student movement member’s iPhone via the notorious Pegasus spyware. This follows a broader trend of increased surveillance activity, prompting Apple to overhaul its threat notification system to provide direct, high-confidence alerts on user lock screens.
Threat Analysis
Mercenary spyware remains a critical threat to global security, with exploit brokers and state-aligned actors continuously refining their delivery mechanisms. The shift toward zero-click exploits—which require no user interaction—has made detection significantly more difficult for the average user. These campaigns are increasingly targeting journalists, diplomats, and activists, often utilizing sophisticated chains that bypass standard iOS security protections.
Technical Details
The recent Pegasus campaign utilizes a zero-click exploit chain that leverages vulnerabilities in core iOS components to achieve arbitrary code execution. Once the initial payload is delivered, the spyware establishes persistence, allowing for the exfiltration of encrypted messaging data, real-time location tracking, and microphone/camera access. Unlike traditional malware, these tools are designed to leave minimal forensic footprints, often residing in volatile memory to evade standard mobile security software.
Attribution Assessment
While the specific operator behind the Serbian incident remains under investigation, the use of Pegasus points to a state-sponsored entity or a high-tier government client. The proliferation of such tools is exacerbated by exploit brokers like the recently sanctioned 'Operation Zero' network, which has been linked to the acquisition of proprietary U.S. government cyber tools. The intersection of commercial spyware and state-level intelligence operations continues to blur the lines of attribution.
Implications
The widespread use of mercenary spyware against political figures and activists undermines democratic processes and individual privacy. The fact that even members of the European Parliament investigating these very tools have been targeted highlights the brazen nature of these actors. As these tools become more accessible through the black market, the risk to global financial and government infrastructure grows exponentially.
Recommendations
- Enable 'Lockdown Mode' on all iOS devices for high-risk individuals. 2. Regularly update devices to the latest firmware to patch known zero-day vulnerabilities. 3. Monitor Apple’s new on-device threat notifications and seek professional forensic assistance if an alert is received. 4. Avoid clicking suspicious links or interacting with unknown attachments, even if the device is supposedly 'secure'.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware: Apple Issues New Wave of Alerts Across 110 Countries

Escalating Mercenary Spyware Campaign Targets Activists and Politicians Across 110 Countries

