MEFILES · Edition No. 50Today's edition · Archive · RSS
Ten files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of September 3, 2026 →
Zero-Click, Eight Months On

Citizen Lab confirms first Pegasus infection of 2026 on a Serbian student activist’s iPhone

Fourteen people were targeted, including an MP and a local councillor, in what SHARE Foundation calls the largest documented spyware wave in Serbia to date. No customer has been named.

The Citizen Lab, working with Belgrade’s SHARE Foundation, said on 2 September that it had analysed forensic artefacts from the iPhone of a member of Serbia’s student protest movement who had received an Apple Threat Notification. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the lab wrote, finding “high-confidence indicators of infection from a period across December 2025 – January 2026.” The exploit, it said, “has subsequently been patched by Apple as of iOS 18.4.1,” and the infection “would not have been visible to the target, and would give the Pegasus attacker total access to the device.” Citizen Lab’s Bill Marczak is attributed for the implant window. The target is unnamed at their own request and with their consent; the lab is withholding the precise infection time to protect their privacy.

SHARE Foundation said it found 14 people targeted in all, including one member of parliament and a local government official, ahead of local elections in March. At least two further devices carried malware resembling NoviSpy, the implant Amnesty International first exposed in Serbia in December 2024. The wave was discovered in August, after Apple notified users in 110 countries that they had likely been targeted with mercenary spyware. “These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” said Donncha Ó Cearbhaill, head of Amnesty’s Security Lab. Ana Toskic Cvetinovic of Partneri Srbija addressed legality: “There must be a reasoned court decision. To our knowledge, there is no such thing here.” A student identified only as Milica told a Belgrade press conference: “They could access the microphone and camera on the phone and turn them on while we shower or speak about private matters.”

Assessment: Serbia sits outside this desk’s usual map, but NSO Group does not, and this is the year’s first forensic Pegasus confirmation — the benchmark against which every unverified hacktivist claim in the file above should be read. Note the eight-month lag between infection and disclosure: that is the real cost of zero-click tooling, not the intrusion itself. Note too what has not been published. Neither Citizen Lab nor SHARE named a Pegasus customer. Nobody has demonstrated who bought the licence, and reporting that flattens this into “Serbia used Pegasus” is asserting something the labs pointedly did not.

Digital Front MonitorMEFILES tracking
110countries where Apple sent mercenary-spyware notifications in August
Evidence4 cited sources · Citizen Lab · CyberScoop · Reuters · The Star
The file19 Jul: 0 stories22 Jul: 2 stories23 Jul: 1 story24 Jul: 1 story25 Jul: 2 stories26 Jul: 2 stories27 Jul: 2 stories28 Jul: 2 stories29 Jul: 2 stories30 Jul: 2 stories31 Jul: 2 stories1 Aug: 2 stories2 Aug: 2 stories3 Aug: 2 stories4 Aug: 2 stories5 Aug: 2 stories6 Aug: 2 stories7 Aug: 2 stories8 Aug: 2 stories9 Aug: 2 stories10 Aug: 2 stories11 Aug: 2 stories13 Aug: 2 stories14 Aug: 2 stories15 Aug: 2 stories16 Aug: 2 stories17 Aug: 2 stories18 Aug: 2 stories19 Aug: 2 stories20 Aug: 2 stories21 Aug: 2 stories22 Aug: 3 stories23 Aug: 2 stories24 Aug: 3 stories25 Aug: 3 stories26 Aug: 2 stories27 Aug: 2 stories28 Aug: 2 stories29 Aug: 2 stories30 Aug: 2 stories31 Aug: 2 stories1 Sept: 2 stories2 Sept: 2 stories3 Sept: 2 stories
Digital Front Monitor · 44 editions since 19 July 2026 · 87 stories filed · 2 in this edition