Skip to main content
Emerging ThreatsMalware & Ransomware

Serbian Activists Targeted by Pegasus, NoviSpy Variant Spyware

Student activist studies at university table with laptop and papers nearby.

"Today, Pegasus is still being used to hack people campaigning for democracy," John Scott-Railton, a senior researcher at the University of Toronto’s Citizen Lab, told reporters — a blunt assessment that accompanies the first confirmed Pegasus infection recorded in 2026 and a concurrent discovery of a NoviSpy variant on devices belonging to Serbian student activists and others.

What researchers say they uncovered

The SHARE Foundation reported that investigators found 14 people targeted in this campaign, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed, with “high probability,” that a student activist’s device was infected with NSO Group’s Pegasus spyware. Amnesty International corroborated that two devices contained a new version of the NoviSpy spyware. SHARE described the event as the largest documented wave of such surveillance in Serbia to date.

NoviSpy variant infections and the circumstances reported

SHARE Foundation researchers said at least one NoviSpy variant infection occurred after police took a student’s phone during questioning. The same spyware was also found on another device after private messages from that phone were published by a media outlet that favors the ruling party, SHARE reported. Both SHARE and Amnesty International said forensic signs point to involvement by Serbian police or the state secret service in those NoviSpy cases. Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, summarized the findings: “These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” and added that the evidence suggests infections are being carried out during detention by the Serbian authorities.

How the Pegasus infection was detected and the technical timeline

Citizen Lab reported the Pegasus infection on the student’s device was delivered via a zero-click exploit, meaning the device was hacked without any interaction by the victim. The organization dated the active exploit window to December of last year through January of this year. Citizen Lab drew a direct line in method and motive back to the earliest public discovery of Pegasus a decade ago, when the tool targeted a pro-democracy activist. John Scott-Railton emphasized the continuity: “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.” The research note also reminded readers that it remains rare for investigators to determine definitively who ultimately operated Pegasus in any given case.

Vendor responses and mitigation reported

NSO Group’s stated position is that its spyware is intended for use against terrorism and crime and that it stops abuses it discovers; that statement was included in the reporting alongside the forensic findings. Apple issued threat notifications to the affected targets, and Bill Marczak, a senior researcher at Citizen Lab, told CyberScoop: “Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS.” That sequence — detection, vendor notification, and a vendor patch — is described in the published account as the mechanism that disrupted the specific zero-click exploit used in the Pegasus case.

How Serbian student activists, Serbian security services, and researchers are likely to respond

  • Serbian student activists and opposition-aligned figures: Having been identified as targets, activists will likely prioritize device hygiene and take-up of vendor updates; the SHARE Foundation described this as the largest wave so far, and those named were prominent enough to include a member of parliament and a local official.
  • Serbian police or secret service: Both SHARE and Amnesty International framed the NoviSpy infections as consistent with operations carried out during detention, a claim that places the spotlight on domestic security services and their practices during police questioning and detention.
  • Digital-rights researchers (Citizen Lab, Amnesty, SHARE): These groups will continue forensic analysis and public disclosure — Citizen Lab supplied the technical attribution timeline and Amnesty supplied corroborating forensic assessments — and will likely press for transparency around how the infections occurred and who authorized them.

The infections were reported to coincide with an intensifying political cycle: SHARE noted the discoveries came as Serbia prepared for local elections in March that had been viewed as a test for the ruling Serbian Progressive Party and as student protests grew following the 2024 Novi Sad railway station canopy collapse and ahead of October parliamentary elections. Taken together, the forensic findings, vendor notifications, and the political timing amount to the clearest public account yet of a coordinated surveillance wave affecting activists, elected officials and local administrators in Serbia.

Two clear questions remain in the record given in the public reporting: who deployed Pegasus in this instance, and whether domestic authorities will provide a public accounting of the NoviSpy infections that SHARE and Amnesty link to police or secret service practices. For now, researchers say the infections are the largest documented wave in Serbia to date; Apple’s patching has neutralized the specific exploit used in the Pegasus case, but the discoveries underline that spyware remains an active tool against people campaigning for democracy, according to the forensic teams involved.

https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/