
Serbian Civil Society Targeted by Pegasus Zero-Click Exploits Ahead of National Elections
Citizen Lab and SHARE Foundation confirm at least 14 Serbian activists and opposition members were targeted with NSO Group’s Pegasus spyware via iMessage zero-click exploits.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Serbia
- Confidence:
- Confirmed
- Source:
- Citizen Lab / SHARE Foundation
- Read Time:
- 4 min
Executive Summary
On September 2, 2026, the SHARE Foundation and Citizen Lab released a joint report detailing a significant wave of mercenary spyware infections targeting Serbian civil society. At least 14 individuals, including student activists, opposition lawmakers, and local councilors, were identified as targets of NSO Group’s Pegasus spyware. This discovery follows a massive global notification campaign by Apple, which alerted users in 110 countries to potential state-sponsored surveillance. The timing is particularly sensitive, occurring between the March local elections and the upcoming parliamentary elections in October.
Threat Analysis
The campaign represents the largest documented use of advanced surveillance technology in Serbia to date. The targeting of the student protest movement, which has been active since late 2024, suggests a strategic effort to suppress political dissent and monitor organizational efforts. Unlike broad cybercriminal activity, these attacks are highly surgical, focusing on individuals who pose a perceived threat to the current political establishment. The use of mercenary tools allows actors to bypass traditional security measures with minimal footprint, making detection nearly impossible without manufacturer-level telemetry.
Technical Details
Forensic analysis by Citizen Lab confirmed the use of a zero-click iMessage exploit to deliver the Pegasus payload. The infections occurred between December 2025 and January 2026, though the full scope of the campaign was only realized following Apple’s August 2026 threat notifications. The exploit chain bypasses standard iOS protections by leveraging vulnerabilities in the BlastDoor framework or similar message-processing components. Once installed, Pegasus grants the operator full access to the device’s microphone, camera, encrypted messages (Signal, WhatsApp), and real-time location data. The "iceberg" effect noted by researchers suggests that for every confirmed infection, dozens more likely remain undetected due to the short shelf-life of these high-cost exploits.
Attribution Assessment
While Apple does not officially attribute these attacks to specific governments, the technical indicators point directly to NSO Group’s Pegasus platform. The SHARE Foundation’s investigation highlights that the targets are exclusively domestic political opponents and activists, strongly suggesting that the client is a state entity with a vested interest in Serbian internal politics. Previous reports have also linked Serbian authorities to the use of other forensic tools like Cellebrite and NoviSpy, indicating a long-standing pattern of domestic digital surveillance.
Implications
This development underscores the growing normalization of mercenary spyware in European domestic politics. The ability of state actors to purchase "surveillance-as-a-service" lowers the barrier to entry for sophisticated espionage, threatening the integrity of democratic elections. Furthermore, the reliance on Apple’s notification system highlights a critical gap in independent mobile security; without manufacturer alerts, most victims would never know their devices were compromised.
Recommendations
Encrygma recommends that high-risk individuals in the Balkan region immediately enable Apple’s Lockdown Mode, which significantly reduces the attack surface for zero-click exploits. Organizations should implement strict communication protocols, utilizing "disappearing messages" and hardware-backed security keys. Additionally, civil society members should seek forensic audits from organizations like the Digital Security Helpline if they receive official threat notifications.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
