Advertisement

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
This aerial photograph shows demonstrators and students as they gather in front of Serbia's Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)

Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date.

The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed the Pegasus infection of a student activist with “high probability,” while Amnesty International confirmed that two devices had been infected with a new version of the NoviSpy spyware.

The SHARE Foundation noted that the infections coincided with the build-up to key local elections in March that were viewed as a test of the ruling Serbian Progressive Party, with student protests rising in the wake of the 2024 Novi Sad railway station canopy collapse, and in advance of October parliamentary elections.

Serbian activists have found themselves targeted with spyware numerous times before, including by Pegasus and NoviSpy. But the SHARE Foundation said this was the biggest wave there so far.

Advertisement

Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.

NoviSpy variant infections

One NoviSpy variant infection came after authorities took a student’s phone during police questioning, and the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party, SHARE Foundation said.

The SHARE Foundation said signs point to Serbian police or secret service being behind the NoviSpy variant cases, with Amnesty International offering a similar assessment. 

“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop. “As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities.”

Advertisement

Pegasus infection

In the case of the infection from NSO Group’s Pegasus spyware, it’s rare for investigators to determine who specifically made use of it, although they found that the student’s device was hacked with a Pegasus zero-click exploit from December of last year to January of this year. The infection came via a zero-click exploit — meaning without victim interaction.

But Citizen Lab said the Serbian case harkens back to the first discovery of Pegasus a decade ago when it was against a pro-democracy activist, Ahmed Mansoor.

“Today, Pegasus is still being used to hack people campaigning for democracy,” said John Scott-Railton, senior researcher. “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”

NSO Group maintains that its spyware is for usage against terrorism and crime, and that it halts any abuses it discovers.

Advertisement

The spyware discoveries in Serbia came after Apple sent threat notifications to the targets.

“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” said Bill Marczak, senior researcher at Citizen Lab.

Latest Podcasts