Citizen Lab confirms first Pegasus infection of 2026 on a Serbian student activist’s iPhone
Fourteen people were targeted, including an MP and a local councillor, in what SHARE Foundation calls the largest documented spyware wave in Serbia to date. No customer has been named.
The Citizen Lab, working with Belgrade’s SHARE Foundation, said on 2 September that it had analysed forensic artefacts from the iPhone of a member of Serbia’s student protest movement who had received an Apple Threat Notification. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the lab wrote, finding “high-confidence indicators of infection from a period across December 2025 – January 2026.” The exploit, it said, “has subsequently been patched by Apple as of iOS 18.4.1,” and the infection “would not have been visible to the target, and would give the Pegasus attacker total access to the device.” Citizen Lab’s Bill Marczak is attributed for the implant window. The target is unnamed at their own request and with their consent; the lab is withholding the precise infection time to protect their privacy.
SHARE Foundation said it found 14 people targeted in all, including one member of parliament and a local government official, ahead of local elections in March. At least two further devices carried malware resembling NoviSpy, the implant Amnesty International first exposed in Serbia in December 2024. The wave was discovered in August, after Apple notified users in 110 countries that they had likely been targeted with mercenary spyware. “These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” said Donncha Ó Cearbhaill, head of Amnesty’s Security Lab. Ana Toskic Cvetinovic of Partneri Srbija addressed legality: “There must be a reasoned court decision. To our knowledge, there is no such thing here.” A student identified only as Milica told a Belgrade press conference: “They could access the microphone and camera on the phone and turn them on while we shower or speak about private matters.”
Assessment: Serbia sits outside this desk’s usual map, but NSO Group does not, and this is the year’s first forensic Pegasus confirmation — the benchmark against which every unverified hacktivist claim in the file above should be read. Note the eight-month lag between infection and disclosure: that is the real cost of zero-click tooling, not the intrusion itself. Note too what has not been published. Neither Citizen Lab nor SHARE named a Pegasus customer. Nobody has demonstrated who bought the licence, and reporting that flattens this into “Serbia used Pegasus” is asserting something the labs pointedly did not.