News Room
16
Share
Serbian Civil Society Targeted by Pegasus Zero-Click Exploits Ahead of National Elections
criticalOffensive Tools

Serbian Civil Society Targeted by Pegasus Zero-Click Exploits Ahead of National Elections

Citizen Lab and SHARE Foundation confirm at least 14 Serbian activists and opposition members were targeted with NSO Group’s Pegasus spyware via iMessage zero-click exploits.

03 September 2026Last updated 03 September 20264 min readCitizen Lab / SHARE Foundation
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Nation-State
Geography:
Serbia
Confidence:
Confirmed
Source:
Citizen Lab / SHARE Foundation
Read Time:
4 min

Executive Summary

On September 2, 2026, the SHARE Foundation and Citizen Lab released a joint report detailing a significant wave of mercenary spyware infections targeting Serbian civil society. At least 14 individuals, including student activists, opposition lawmakers, and local councilors, were identified as targets of NSO Group’s Pegasus spyware. This discovery follows a massive global notification campaign by Apple, which alerted users in 110 countries to potential state-sponsored surveillance. The timing is particularly sensitive, occurring between the March local elections and the upcoming parliamentary elections in October.

Threat Analysis

The campaign represents the largest documented use of advanced surveillance technology in Serbia to date. The targeting of the student protest movement, which has been active since late 2024, suggests a strategic effort to suppress political dissent and monitor organizational efforts. Unlike broad cybercriminal activity, these attacks are highly surgical, focusing on individuals who pose a perceived threat to the current political establishment. The use of mercenary tools allows actors to bypass traditional security measures with minimal footprint, making detection nearly impossible without manufacturer-level telemetry.

Technical Details

Forensic analysis by Citizen Lab confirmed the use of a zero-click iMessage exploit to deliver the Pegasus payload. The infections occurred between December 2025 and January 2026, though the full scope of the campaign was only realized following Apple’s August 2026 threat notifications. The exploit chain bypasses standard iOS protections by leveraging vulnerabilities in the BlastDoor framework or similar message-processing components. Once installed, Pegasus grants the operator full access to the device’s microphone, camera, encrypted messages (Signal, WhatsApp), and real-time location data. The "iceberg" effect noted by researchers suggests that for every confirmed infection, dozens more likely remain undetected due to the short shelf-life of these high-cost exploits.

Attribution Assessment

While Apple does not officially attribute these attacks to specific governments, the technical indicators point directly to NSO Group’s Pegasus platform. The SHARE Foundation’s investigation highlights that the targets are exclusively domestic political opponents and activists, strongly suggesting that the client is a state entity with a vested interest in Serbian internal politics. Previous reports have also linked Serbian authorities to the use of other forensic tools like Cellebrite and NoviSpy, indicating a long-standing pattern of domestic digital surveillance.

Implications

This development underscores the growing normalization of mercenary spyware in European domestic politics. The ability of state actors to purchase "surveillance-as-a-service" lowers the barrier to entry for sophisticated espionage, threatening the integrity of democratic elections. Furthermore, the reliance on Apple’s notification system highlights a critical gap in independent mobile security; without manufacturer alerts, most victims would never know their devices were compromised.

Recommendations

Encrygma recommends that high-risk individuals in the Balkan region immediately enable Apple’s Lockdown Mode, which significantly reduces the attack surface for zero-click exploits. Organizations should implement strict communication protocols, utilizing "disappearing messages" and hardware-backed security keys. Additionally, civil society members should seek forensic audits from organizations like the Digital Security Helpline if they receive official threat notifications.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo